Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

Andrew, you've taken this road for years now and have only been rude and dismissive to me on Discord, IRC and GitHub for a while, despite my many attempts to reach common ground and discuss what happened with the DOS vulnerability I found in the standard library, one you acknowledged was unfortunate. You dismissed it saying that Zig should not be used in production until v1, but I (correctly) pointed out that won't stop people from using it in production. Now, for example, we have Bun.sh, which worries me that the standard library has other "unfortunate" vulnerabilities you have also chosen to ignore that are making their way into production.

There's clearly nothing more I can say to you; I'm tired of the emotional and childish responses to my attempts to reach out. I've expressly avoided using your name and have tried to keep my critiques civil when discussing Zig the few times I have. However, you seem to find the comments every time despite this.

I wish you and Zig the best of luck.

---

andrewrk — 04/02/2020 there's no such thing as security vulnerabilities until post-1.0, which is why nobody should be using zig in production yet



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: