There are times where I envy the straight forward rationale of these beasts of burden we instruct in our daily routines. The name of the package is irrelevant to them, its just an identifier that represents a thing that does stuff. As software engineers you'd hope we were some of the most logical peoples of this planet but then we find ourselves tripping over our own societal taboos and inferences we are perceiving t…
I paid attention to this only because we helped with Github's audit of the code, and am motivated to comment here primarily as an opportunity to say:
Make sure your Markdown library is secure.
Everyone seems at some point to end up with a C-language Markdown implementation, and nobody I know of has managed to implement Markdown in C without memory corruption bugs... you know, the kind that let attackers upload their own code onto your servers.