logoalt Hacker News

raframyesterday at 4:08 PM3 repliesview on HN

No. A Snowflake maintainer opened a PR, Copilot suggested a change (introducing a vulnerability), the maintainer accepted and committed it to their PR, and another Snowflake maintainer approved and merged the PR.


Replies

otterleyyesterday at 6:00 PM

I don't see anything in the article that says that two maintainers, let alone one, reviewed the PR manually and approved it before merging. Where are you getting this information from?

show 2 replies
lelanthranyesterday at 4:46 PM

And that's going to continue because no one is reading the code even when they approve it.

It's a very strange thing indeed, but not unexpected: we warned that skills not used will eventually atrophy.

rawgabbityesterday at 5:18 PM

Thanks.