Elektrine lite

← Feed

@charette@mstdn.ca

Post #4169455

2026-07-28 17:20 UTC

Another LLM-generated security report e-mailed to me today concerning some code I didn't write but I maintain. Requires users to load invalid configuration files to exploit a buffer overrun. I've been given 90 days to fix the problem. Note I don't get paid to work on open-source software. And users shouldn't be loading random invalid configuration files. This is just like e-mail. When there is zero cost associated with sending out junk mail, then you guarantee that junk mail will continuously be sent out. #Darknet #YOLO #CVE

Replies (1)

  • @charette@mstdn.ca 2026-07-28 17:45

    I'd be less annoyed if one or more of the following were true: If I was paid to maintain the Darknet/YOLO codebase.If the user had submitted a PR with the proposed fix, showing they were actually part of the Darknet/YOLO community and not someone scanning thousands of github repos looking for problems.If the report that was sent to me wasn't so obviously written by a LLM.

    Open ##4169910