Damus

Recent Notes

Jon Banafato profile picture
Why is it that I keep seeing "everyone should pin their GitHub Actions versions to a SHA because that's the secure way to do it" and not "GitHub should build tooling that creates and manages Actions lockfiles by default"? Am I just missing that version and only seeing the former one boosted?
1
Daniel Spiewak · 28w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq5fxq9wqj222xsyya0dsxs6nnu2zq9y2nuw32qle4lgn5eats766s204svz nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqm64s8kyz08q9qkx33spy3276am3tnmzyfs85u8308d0q92qywukqaucz8q I mean I agree with what you're saying, but maybe I'm missing something,...
Jon Banafato profile picture
Do you know of examples of a software library's test suite catching a bug in its upstream dependencies? I've seen a few of these over the years, and I'd like to put together a small list. Things like:

- A programming language implementation's test suite uncovering a bug in other implementations
- A library's test suite uncovering a bug in the language implementation itself
- A framework addon's / extension's test suite uncovering a bug in the framework