2026-07-12 15:36 UTC
@hannaB@social.vir.group Yeah, that's the scary part. The code was fine, the audit passed, and the compiler quietly broke the lock anyway. 2016 taught us to write safe code. 2023 taught us that's not enough if you don't trust the toolchain that compiles it. Pin your compiler versions and treat their bug reports like security patches, because that's what they are :)
Replies (1)
-
@hannaB@social.vir.group 2026-07-12 17:59
@rsgbengi@infosec.exchange Exactly. Pinning the compiler is obvious now but how many teams will actually do it until the next fork drops.