Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This particular line in the developer's response[1] leads me to believe they don't - or at least don't properly - validate third party dependency changes, which is even more worrying if I'm honest:

  > I will look into why Sentry.io is being contacted so often! This is strange as unless they changed their SDK/framework, is only supposed to happen on a crash report.
1: https://github.com/objective-see/LuLu/issues/488#issuecommen...


That's a poor characterisation, I'm not convinced any developer can say with 100% certainty they've never missed anything in the release notes of their dependencies or had any unexpected behaviour in changes that made it to production. Mistakes happen.


The nature and capabilities of these products makes me significantly less forgiving towards these sorts of mistakes, however.

Just to be clear I have no ill will towards this developer or their products.


I agree with sibling: I think you're giving it an uncharitable interpretation. There is an open issue and they are investigating to improve the situation.


You’d think, if they wanted telemetry so badly they are prepared to deal with the fallout, they’d be on top of the information collected by that telemetry.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: