Maintainers are now self-sabotaging their work in order to take political or economic stances, a practice referred to as "protestware". In this poster, we present our approach to understand how the discourse about such an attack went viral, how it is received by the community, and whether developers respond to the attack in a timely manner. We study two notable protestware cases, i.e., Colors.js and es5-ext, comparing with discussions of a typical security vulnerability as a baseline, i.e., Ua-parser, and perform a thematic analysis of more than two thousand protest-related posts to extract the different narratives when discussing protestware.
翻译:维护者现在为了表达政治或经济立场而自我破坏其作品,这种做法被称为“抗议软件”。在本海报中,我们提出了一种方法,以理解此类攻击的讨论如何迅速传播、社区如何接受它,以及开发者是否及时对攻击做出响应。我们研究了两起显著的抗议软件案例,即Colors.js和es5-ext,并以典型安全漏洞Ua-parser的讨论为基线进行比较,对超过两千条与抗议相关的帖子进行主题分析,以提取讨论抗议软件时的不同叙事。