Hacker Newsnew | past | comments | ask | show | jobs | submit | mldevv's commentslogin

Its been almost a week, what correction would you like to make to this? You've been dodging and the community deserves honest answers.


Yes and that is a huge deal - I made this point to others that it shouldn't be considered a minor version change


Right. And actually this small detail is emblematic of the whole problem.

When you roll out an auto-updates mechanism you're saying to the people who enable it "you can trust us to do the right thing with your project while you are elsewhere -- this is a risk but it's one we manage for your benefit".

If you roll out a change for purely political/commercial reasons that are ultimately not your end user's concern -- we're not a party to that lawsuit -- then you're undermining the trust in that mechanism entirely.

It was a stupid, arrogant, underhanded thing to do.


As an agency dev, this is the shit they don't think about. In my case, all that would have to be billed or go through pro-bono approval process.

"Just update it!" Until it all goes to shit, and we have to triage the whole mess.

Sorry you are dealing with this, I have spent the better part of the weekend trying to get them to understand this was inevitable.

Devs: "Don't deploy on Fridays" A8C/Matt: "We will deploy on SATURDAYS"


We finished nearly half. Urgent ones are done but I need to spend another 5-10 hours tomorrow. Today really sucked.


I agree with this take, professionally. People have generally saw their investment as a positive, whether its deemed "enough" or not


My opinion as well as many as my peers is that ACF could have been rolled into core or bought by Matt long long before it was acquired by WPE, which most of us found as a good thing, being that its a critical plugin and gained long term support.

Plugins have bumps, that's part of the growth, and some of the changes ACF have made as of recent years, even the ones I disagree with, seem well intentioned and not malicious. I can't say the same for what is happening right now.


They use the parts of wordpress that are specifically built in to make modifications, as any other site maintainer would hosting their own install.

You are mistaken.


WP and/or A8C took over the existing plugin, so that sites that have auto-update on were automatically bumped to the SCF version instead of the historical ACF which obviously had a different team of maintainers


(community member, not affiliated with WP, WPE, or A8C)

I can confirm this has been escalated internally in the WP slack.

I can also provide this context which I found concerning, given the way this was taken over and rolled out on a Saturday afternoon, of which I have also been dragged into now as a fellow site maintainer.

- Matt Mullenweg "in a few days we'll have a Github where people can get involved, and we can also set up proper build systems, etc"

So its all in flux obviously. I let them know the same thing, that I find this as a malicious supply chain attack that is affecting the community.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: