Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Where's the source code? #13

Closed
Zulu-Inuoe opened this issue Jul 19, 2023 · 6 comments
Closed

Where's the source code? #13

Zulu-Inuoe opened this issue Jul 19, 2023 · 6 comments

Comments

@Zulu-Inuoe
Copy link

This is an interesting venture, but my concern is that I don't see any source provided for SponsorLink.
Where does the dll on NuGet come from?

Thanks.

@kzu
Copy link
Member

kzu commented Aug 4, 2023

Hi @Zulu-Inuoe! Thanks for your interest in SponsorLink.

Given that the goal of SponsorLink is to provide a way to ensure users get notified about their sponsorship status, I considered that making the source available of how the check is implemented, would only serve to illuminate those wanting to skip the check.

The details of how it works are explained on my blog, just to get a sense of how it ties in with the build and the IDE experience.

@Zulu-Inuoe
Copy link
Author

I encourage you to reconsider this position, as security by obscurity is a well known trope.
That said, as it stands for me, this makes projects using this software unusable as I don't want to be running unknown and untrusted software on my developer's machines.

@Zulu-Inuoe Zulu-Inuoe closed this as not planned Won't fix, can't repro, duplicate, stale Aug 6, 2023
@ripvannwinkler
Copy link

How to kill a project in 1 easy step...

@sbergot
Copy link

sbergot commented Aug 9, 2023

This project collects the email addresses of every user compiling this library without their consent. How do you make this compliant with GDPR?

@lucas-zimerman
Copy link

How to kill a project in 1 easy step...

I dont think he's killing the project, but more likely other projects who decide to include SponsorLink are shooting themselves by adding it without even noticing or even opening a Pull Request.
It gives the impression someone got access to their accounts and just shipped a fast spyware to production.

@kzu
Copy link
Member

kzu commented Aug 18, 2023

It's all OSS on this same repo now. Closing and locking. Thanks!

@devlooped devlooped locked as resolved and limited conversation to collaborators Aug 18, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants