logoalt Hacker News

Twirrimtoday at 2:47 PM3 repliesview on HN

You can't rely on people spotting the significance of such changes


Replies

eithedtoday at 2:58 PM

Tests would have caught it = https://github.com/rhysd/actionlint injection check

show 1 reply
dv_dttoday at 3:03 PM

I have been talking to people who want to autoreview and autoapprove "minor" AI prs. For security especially, I think if the models weren't enough to prevent the issues, they aren't enough to judge what is minor.

fn-motetoday at 2:53 PM

^^

Absolutely.

Nothing in the PR jumps out as a red flag. Unless you know how the internals work, I suppose.

show 2 replies