| ▲ | Twirrim 2 hours ago | ||||||||||||||||||||||
You can't rely on people spotting the significance of such changes | |||||||||||||||||||||||
| ▲ | eithed 2 hours ago | parent | next [-] | ||||||||||||||||||||||
Tests would have caught it = https://github.com/rhysd/actionlint injection check | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | dv_dt an hour ago | parent | prev | next [-] | ||||||||||||||||||||||
I have been talking to people who want to autoreview and approve "minor" AI prs. For security especially, I think if the models weren't enough to prevent the issues, they aren't enough to judge what is minor. | |||||||||||||||||||||||
| ▲ | fn-mote 2 hours ago | parent | prev [-] | ||||||||||||||||||||||
^^ Absolutely. Nothing in the PR jumps out as a red flag. Unless you know how the internals work, I suppose. | |||||||||||||||||||||||
| |||||||||||||||||||||||