He made an attempt to patch upstream, was shot down, and then proved his point without hurting anyone. Maybe not the best way to get the issue out, but we are talking about it and it wasn't especially harmful. Mission accomplished?
I don't know how else he could have done this. He was being ingored!
> He made an attempt to patch upstream, was shot down, and then proved his point without hurting anyone.
Assuming no economic impact to github you mean. If paying users leave because they feel github is no longer safe for private repos because of this, that is harm.
I imagine a bank would be far more grouchy if someone exploited a vulnerability and deposited one cent into someone's account "just to show there was a vulnerability" then publicized it, without talking to them about it first. <sarcasm>No harm done right?</sarcasm>
Now, I am not saying that it is bad that this github vulnerability was found and fixed. I am very glad! But I think it could have been far more responsibly done.
He didn't try to "patch" anything -- there was no code attached to the issue he filed -- and he wasn't ignored.
What _really_ happened is that he was told, "no, we think that this is the application developer's responsibility." He became frustrated that the response wasn't what he had anticipated, so instead of acting like a mature software developer he started acting like a petulant child.
The point is, this Github exploit could still exist even if some protections were set by the framework. Developers should take their app's security into their own hands (and I'm sure Github does) by employing a solution similar to attr_accessible.
I don't know how else he could have done this. He was being ingored!