Nikita Karamov
🐍 > 🦀
An open-source Python and JavaScript developer. I made Shareon and Share2Fedi
In my free time: YouTube, Cooking, Cycling
The street that my mum lives in is a one-way street, but wasn't marked as such on #Google Maps. This caused many drivers to drive the wrong way. I have tried to edit it on Google Maps (there is such functionality), but to no avail. No matter how often I submitted a change (with photos of street signs!), Google said "Sorry, we could not verify it".
Solution: Edit the street on #OpenStreetMap! A few months after I did this, Google seems to have stolen the data, as it regularly does, and now the street is correct in both datasets!
Looking at the diff between two minor versions of a GitHub Action for installing Node.js. Not many changes: Just a few dependency version updates and a few CI changes. The source of the action itself is unchanged.
And yet, the files that run in CI have 95k additions and 124k deletions. Two hundred and nineteen thousand modified lines. There is no way anyone will ever look at and audit those changes. And all that in an action whose only task is to download and unpack Node.js. How have we become okay with running this much obfuscated code as part of our critical supply chain?