- They are very open about security vulnerabilities and fix them fast.
- There are some inherent defects in their software that cause these security vulnerabilities to come up so frequently.
I'd like to believe it's the first.
EDIT: formatting.
- They are very open about security vulnerabilities and fix them fast.
- There are some inherent defects in their software that cause these security vulnerabilities to come up so frequently.
I'd like to believe it's the first.
EDIT: formatting.
They are also churning at a pretty insane rate due their release schedule. I did a very basic analysis of their repos at
http://gitsense.github.io/blog/motion-bubble-charts.html
And this is the churn for this month in their master and 8-7-stable branch
I also included the https://github.com/atom/atom master branch (blue line) for comparison.
In order to get a better picture what what's going on, I'll need to cross reference the churn to security issues, but this isn't something my tool will support until later in the year.
- We're very open about vulnerabilities and fix them fast
- We have a large install base, in particular >100k Community Edition installations
- Our source code is open and not obfuscated. It's easier to mess around in it for anyone interested, even when it's running.
- We regularly have security researchers perform audits
- Our rate of change (as mentioned by others) is very high
Relevant: https://twitter.com/tenderlove/status/725370404513017856
As with any software project; there will be bugs.
As with any open source project; there will be eyes on the code.