• jackpot@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      this isnt worth the time, it’s not a dependency of a huge piece of software

      • erAck@discuss.tchncs.de
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        Malicious account holders with a long term goal need to build reputation. It doesn’t matter much that such an app isn’t a dependency of other software.

        • steeznson@lemmy.world
          cake
          link
          fedilink
          arrow-up
          1
          ·
          6 months ago

          Practically every FOSS project is actively looking for volunteers/maintainers all of the time. More contributors are not problematic.

          The xz problem was that they socially engineered the main dev into giving them the keys to the kingdom.

          • erAck@discuss.tchncs.de
            link
            fedilink
            arrow-up
            1
            ·
            6 months ago

            Making one a maintainer (with merge and possibly even direct commit/push permissions) is handing them a key to the kingdom. Recruiting a maintainer out of the blue without them being already contributor and long term participant in the project is questionable.