-
step in and help review a few PRs
-
help the project triage/reproduce bugs
-
if code in the PR looks complicated or is hard to understand, ask for an explanation
-
express your gratitude to the maintainers
-
make your company sponsor projects they depend on
https://mastodon.social/@bagder/112194895793007918
Daniel is the creator of cURL : https://daniel.haxx.se/blog/2021/03/30/howto-backdoor-curl/
is “step in and help review a few PRs” really that helpful? like… oh great, now this one person that i don’t trust is telling me that the other person that i don’t trust made some code that i should merge
How does one become trusted? If they regularly review and provide feedback that you agree with it can really speed up the process, even if you’re still double checking.
Exactly. At first it means nothing. Over time they can begin to trust you.
@twei Well of course as an outsider you can’t call the “All clear”. But you can raise concerns and ask questions about binary files, obfuscated parts, you can checkout the branch and run it, … if you find something, say it, it’s easy to verify your claim. Saying “I didn’t find any problem” is not so helpful, as that is also not so easy to verify, and doesn’t prove the absence of problems. But pointing to a problem proves the existence of problems.