Until you unintentionally pull in a vulnerability or intentional backdoor. Every PR needs to be reviewed.
The point was that you can also just reject an PR on the basis of what it purports to implement, or even just blanket ignore all PRs. You can't pull in what you don't... pull in.
> Every PR needs to be reviewed.
Why would you review a PR that you are never going to merge?
The point was that you can also just reject an PR on the basis of what it purports to implement, or even just blanket ignore all PRs. You can't pull in what you don't... pull in.