Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The pull request model is fine for open source development, but it’s been a move backwards for internal development

The more paranoid would claim that requiring PRs that then require approvals prevents a malicious engineer from adding an obvious back door to the code.

You would hope you can trust your co-workers, but sometimes a hack is an inside job.



There are all sorts of workflows that can be arranged to prevent that while still having optimistic continuous integration on trunk.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: