-
step in and help review a few PRs
-
help the project triage/reproduce bugs
-
if code in the PR looks complicated or is hard to understand, ask for an explanation
-
express your gratitude to the maintainers
-
make your company sponsor projects they depend on
https://mastodon.social/@bagder/112194895793007918
Daniel is the creator of cURL : https://daniel.haxx.se/blog/2021/03/30/howto-backdoor-curl/
@twei Well of course as an outsider you can’t call the “All clear”. But you can raise concerns and ask questions about binary files, obfuscated parts, you can checkout the branch and run it, … if you find something, say it, it’s easy to verify your claim. Saying “I didn’t find any problem” is not so helpful, as that is also not so easy to verify, and doesn’t prove the absence of problems. But pointing to a problem proves the existence of problems.