TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Moq – Privacy issues with SponsorLink, starting from version 4.20

49 点作者 DishyDev将近 2 年前

2 条评论

tailspin2019将近 2 年前
As a long time user of Moq, I’m horrified by this. I think the author has now reverted this but I’ll be moving away from this library anyway.<p>I’ll also be reevaluating all my Nuget dependencies and their potential security risks (so indirectly, one good thing I guess).<p>Reading all the comments on GitHub though, I’ve got to feel for the dev a bit - he has half the .NET community all piling on after years of his hard work likely being under appreciated (as is often the case with OSS developers).<p>He’s made a big misstep with this, and broken a lot of trust, but it genuinely doesn’t look like malice - rather just (really) terrible judgement.<p>Not excusing his mistake, but wow, I wouldn’t want to be on the receiving end of all that anger.<p>Personally I feel there is a limit to how angry I’m entitled to be after years of benefitting from this guys work without paying him a penny.<p>It’s really just a sad situation all round.<p>Edit: more info on the dev’s reasoning behind this change in his original blog post from January:<p><a href="https:&#x2F;&#x2F;www.cazzulino.com&#x2F;sponsorlink.html" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.cazzulino.com&#x2F;sponsorlink.html</a>
评论 #37064246 未加载
minajevs将近 2 年前
Library author decisions aside, the implications for the .NET ecosystem are insane.<p>.NET Analyzers spawning processes, especially in an elevated environment. Pausing builds for 100ms for non-paying users. Silently leaking millions of user emails.<p>That all seems much dirtier than core-js drama.