I don't understand why this is an issue for the current employees. Surely you hire a bunch of sales people and a bunch of consultants to help with on-boarding/support and place them in a separate floor or building. They don't really need to interact with developers. The 'brogrammers' just carry on as normal and some of their work is now adding features to help support enterprise requirements. Unless your sitting a co…
Enterprise sales people can make a habit of selling things that the product can't currently do, and then forcing engineering to make it a reality on a compressed timeline because "this is a deal we can't afford to lose." Repeatedly. No idea if that's happeing at GitHub, but I've seen it happen a few other places, and it sucks for the engineering and product teams even if the sales people are in a different state. In…
GitHub is apparently in crisis again
81–90 of 159 posts
Re: GitHub is apparently in crisis again
#82Oh my goodness. Is this article just plain wrong, or does a large enough subset of Silicon Valley & friends actually do this that they mistook that behavior as including the other 99% of the software development world?
Re: GitHub is apparently in crisis again
#83* Code browsing is terrible and without `octotree` I don't know what I would do.
* Organization view is a joke; once you have 50 repos, good luck finding anything there.
* There is no way of managing anything on higher level, only per repo. I can live with that but there are people who want to track issues across the projects. And then one ends up with JIRA for issue tracking (the horror!).
* Edit: code search is also a joke or even an insult
After all these years in business, GitHub website doesn't offer any insights into your git repo over git command line and is probably worse than command line for many use cases. That is simply disappointing.
Re: GitHub is apparently in crisis again
#84Earlier quoted context omitted.
Enterprise sales people can make a habit of selling things that the product can't currently do, and then forcing engineering to make it a reality on a compressed timeline because "this is a deal we can't afford to lose." Repeatedly. No idea if that's happeing at GitHub, but I've seen it happen a few other places, and it sucks for the engineering and product teams even if the sales people are in a different state. In…
As someone who used to sit between the engineering and sales teams from the engineering side, I actually empathize with the sales teams more than most engineers. You aren't there to write code in a vacuum. There are a lot of time it IS a deal you can't afford to lose.
Re: GitHub is apparently in crisis again
#85Earlier quoted context omitted.
We welcome all the paranoia we can get. Please be informed that multiple organizations have done security audits for GitLab and we have paid external parties to perform them for us. That doesn't mean there are no bugs anymore.
Multiple organizations -> good! :) Not to speak badly about any of my peers in particular, but I've come in after other security auditing teams and found really obvious bugs that they've overlooked. Though I usually give them the benefit of the doubt and omit my feelings when I write my report. Maybe it was a time constraint or a scoping issue that prevented them from seeing it? I have no way of knowing. So, kudos fo…
And you've never missed one, right?
Aside from this, your behavior in this thread is a very loud warning about working with you, particularly telling someone to learn to read below by linking to an app. Handle being questioned a bit better, if you can, and understand that seeing this immediately talks me out of using your services. (Even if you're an oracle who never makes a mistake, as you imply. I'll take my chances with someone a bit more professional.)
Re: GitHub is apparently in crisis again
#86Earlier quoted context omitted.
Multiple organizations -> good! :) Not to speak badly about any of my peers in particular, but I've come in after other security auditing teams and found really obvious bugs that they've overlooked. Though I usually give them the benefit of the doubt and omit my feelings when I write my report. Maybe it was a time constraint or a scoping issue that prevented them from seeing it? I have no way of knowing. So, kudos fo…
> Not to speak badly about any of my peers in particular, but I've come in after other security auditing teams and found really obvious bugs that they've overlooked. And you've never missed one, right? Aside from this, your behavior in this thread is a very loud warning about working with you, particularly telling someone to learn to read below by linking to an app. Handle being questioned a bit better, if you can, a…
Have I overlooked really obvious bugs? None so far that I've been informed of.
I'm not careless when I get paid to audit a project. Of course, I know I'm not perfect either.
One time, I was writing a PoC implementation of AES-CBC and forgot to authenticate the IV (which was included in the message). Luckily, someone called me out on it very early on. (As a result, I'm also more likely to catch this kind of mistake in someone else's work.)
Making mistakes is part of the learning process. Making mistakes when assessing someone else's security is a very real danger. That's why I give GitLab kudos for using multiple organizations.
The moral to the story I was telling, albeit poorly, is that "I think you're doing the right thing by having multiple teams look at your project". But that was my fault for not expressing this clearly enough.
> Aside from this, your behavior in this thread is a very loud warning about working with you, particularly telling someone to learn to read below by linking to an app.
Nobody who contacts my employer deals with me directly. The person who handles clients has people skills. I do the technical heavy lifting.
So, please rest assured, that any "very loud warning" you're reading won't translate into the quality of services we provide, even if I am an asshole on my personal accounts.
> Handle being questioned a bit better, if you can, and understand that seeing this immediately talks me out of using your services. (Even if you're an oracle who never makes a mistake, as you imply. I'll take my chances with someone a bit more professional.)
I don't mind being questioned. I mind people demonstrating a blindness to the qualifiers I explicitly include in my statements.
Re: GitHub is apparently in crisis again
#87When GitHub (which has always been cash-flow positive) took VC money, they said that it wasn't because they needed the money. Rather, they said that the money would be used to fund new projects and directions, and because it brought the VCs in as strategic partners.
Maybe the money did change things -- but the new directions weren't positive, and the strategy suggested by their partners wasn't as beneficial as they thought?
Re: GitHub is apparently in crisis again
#88Earlier quoted context omitted.
> Not to speak badly about any of my peers in particular, but I've come in after other security auditing teams and found really obvious bugs that they've overlooked. And you've never missed one, right? Aside from this, your behavior in this thread is a very loud warning about working with you, particularly telling someone to learn to read below by linking to an app. Handle being questioned a bit better, if you can, a…
Have I overlooked bugs? Sure. Have I overlooked really obvious bugs? None so far that I've been informed of. I'm not careless when I get paid to audit a project. Of course, I know I'm not perfect either. One time, I was writing a PoC implementation of AES-CBC and forgot to authenticate the IV (which was included in the message). Luckily, someone called me out on it very early on. (As a result, I'm also more likely to…
And yet here I am, mentally blacklisting your company. Weird, right? Almost like team matters, and you carry a 'C' in your title, allegedly, so...
It was just informal advice to rein yourself in. Take it or leave it.
Re: GitHub is apparently in crisis again
#89Earlier quoted context omitted.
Have I overlooked bugs? Sure. Have I overlooked really obvious bugs? None so far that I've been informed of. I'm not careless when I get paid to audit a project. Of course, I know I'm not perfect either. One time, I was writing a PoC implementation of AES-CBC and forgot to authenticate the IV (which was included in the message). Luckily, someone called me out on it very early on. (As a result, I'm also more likely to…
> So, please rest assured, that any "very loud warning" you're reading won't translate into the quality of services we provide, even if I am an asshole on my personal accounts. And yet here I am, mentally blacklisting your company. Weird, right? Almost like team matters, and you carry a 'C' in your title, allegedly, so... It was just informal advice to rein yourself in. Take it or leave it.
Okay, I'll take it. It's just really frustrating that this keeps happening even though I take care to choose my words very precisely. Especially qualifiers.
I don't know how to be more explicit than totally explicit. That doesn't even seem possible. Maybe I'm the idiot here.
Re: GitHub is apparently in crisis again
#90I've been on GitHub since the earliest days, and I've definitely noticed that there's something going on -- or the lack of anything going on more like it. When was the last time a big feature that people are actually clamoring for was added to GitHub (and let's not pretend LFS fits that description)? Meanwhile you have the maintainers of the most popular projects publicly begging for changes they've been waiting year…