Elektrine lite

← Feed

@mechko@chaos.social

Post #2469308

2026-05-11 09:04 UTC

Important heads-up to FOSS maintainers by Daniel from curl: "Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools." Since I'm working for Alpha-Omega currently, please reach out to me if you could use some support regarding this. We're setting up various programs to help FOSS maintainers in the times of "high-quality chaos". https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/

Replies (5)

  • @js@nil.im 2026-05-11 09:09

    @mechko@chaos.social Is any open source project in scope? If I maintain an open source project, can I just ask you to run it against my project?

    Open ##2723500

  • @ringods@hachyderm.io 2026-05-11 09:25

    @mechko@chaos.social @purpleidea@mastodon.social FYI 👆🏼

    Open ##2723503

  • @sjaveed@mastodon.social 2026-05-11 10:07

    @mechko@chaos.social in other words, the cURL codebase is, with apologies to Douglas Adams, “Mostly Bugless”?

    Open ##2723504

  • @eliotlear@mastodon.social 2026-05-11 10:22

    @mechko@chaos.social The only thing that's surprising is that it found only one vulnerability. Curl is a monster of a package with huge numbers of dependencies.

    Open ##2723505

  • @gnirre@mastodon.social 2026-05-11 13:13

    @mechko@chaos.social Do you know why it took so long for curl to get access to Mythos? Is there a long line of projects waiting...?

    Open ##2723508