• Sign in
  • Sign up
Elektrine
EN
Log in Register
Modes
Overview Chat Timeline Communities Gallery Lists Friends Email Vault DNS VPN
Back to Timeline
  • Open on social.linux.pizza

Vikunja (/vɪˈkuːnjə/)

@vikunja@social.linux.pizza
mastodon 4.5.9

The open source to-do app to simplify your life. Built by @kolaente@mastodon.social

0 Followers
0 Following
Joined October 28, 2022
Website:
https://vikunja.io

Posts

Open post
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · 1d ago

Cal.com announced they're going closed source. The stated reason: AI has made it too easy for attackers to find bugs in public code.

I've been thinking about this for a bit. It's security-through-obscurity with a 2026 paint job, and I don't buy it.

Kerckhoffs's principle is over a century old: a system should remain secure even when everything about it except the key is public.

LLMs don't change the direction, only the speed. AI scans closed code just fine (fuzzing, binaries, APIs). Hiding the source doesn't remove bugs. It just means whoever finds them has no obligation to tell you first.

From Vikunja's own release notes: CVE-2026-28268, fixed in 2.1.0. Password reset tokens weren't being invalidated after use. The bug had been sitting in the codebase since v0.18.0 in September 2021.

A researcher found it (probably with the help of AI), reported it responsibly, and it got fixed. If the source had been closed, nobody external would have been in a position to catch it.

Every founder who eventually closed their source once said "I promise we won't." I believe they meant it at the time. Circumstances change.

So the better question is: what would have to happen for Vikunja to close? Four structural facts: AGPL-3 license, no CLA, no investors, and anyone can fork today's code.

Transparency trades "bugs found later by the wrong people" for "bugs found earlier by the right ones."

That's the actual tradeoff. Closing the source flips the sign on every term.

https://vikunja.io/changelog/vikunja-stays-open/

View on social.linux.pizza
On Cal.com, AI security reports, and why Vikunja can
vikunja.io

On Cal.com, AI security reports, and why Vikunja can

A response to Cal.com going closed source: why security-through-obscurity doesn

11
0
4
0
Open post
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · Apr 09, 2026

🦙 Vikunja 2.3.0 is out! 11 security fixes, a new plugin system, quick-entry window for the desktop app, Vikunja as an OAuth 2.0 provider, WeKan + CSV imports, and more across 277 commits. Updating soon is highly reccomended!

https://vikunja.io/changelog/whats-new-in-vikunja-2.3.0

View on social.linux.pizza
10
0
6
0
Open post
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · Apr 07, 2026

PSA: there will be a release tomorrow (April 8th) or the day after that with a bunch of security fixes

View on social.linux.pizza
7
0
2
0
Open post
In reply to
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · Mar 23, 2026
@pojntfx@mastodon.social @jonasfranz@gruene.social We have CalDAV support 👀 https://vikunja.io/help/caldav/
View full thread on social.linux.pizza
0
0
0
0
Open post
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · Mar 20, 2026

🔒 Vikunja 2.2.0 is out! 10 security fixes (update now!), plus task duplication, an improved Gantt chart with subtask hierarchy & dependency arrows, and user-level webhooks. 237 commits of goodness 🚀

https://vikunja.io/changelog/vikunja-v2.2.0-was-released

View on social.linux.pizza
8
0
7
0
Open post
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · Mar 19, 2026
PSA: The next Vikunja release will fix 10 (!) CVEs. If all goes well, later today or tomorrow.
View on social.linux.pizza
9
0
5
0
Open post
In reply to
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · Mar 09, 2026
@LilithElina@norden.social @mailbox_org@social.mailbox.org das sollte mit Vikunja ganz gut funktionieren. Für Push-Nachrichten kann ich entweder die Vikunja-App oder die Synchronisation mit Tasks.org empfehlen
View full thread on social.linux.pizza
0
0
0
0
Open post
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · Feb 27, 2026
🎉 Just two days after the last release, Vikunja 2.1.0 is now released! 🔒 Fixes a security issue with password reset tokens and adds a nice touch: checklist indicators now turn green when all items are done! Check out the full release post on the website: https://vikunja.io/changelog/vikunja-v2.1.0-was-released/
View on social.linux.pizza
12
0
7
0
Open post
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · Feb 24, 2026
PSA: Vikunja 1.2.0 will be released tomorrow or the day after. It will fix four (!) critical security vulnerabilities.
View on social.linux.pizza
0
0
0
0
Open post
In reply to
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · Feb 12, 2026
The post is now updated with details about the vulnerability!
View full thread on social.linux.pizza
0
0
0
0
Open post
vikunja
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
Vikunja (/vɪˈkuːnjə/)
Vikunja (/vɪˈkuːnjə/)
@vikunja@social.linux.pizza

The open source to-do app to simplify your life. Built by @ kolaente

social.linux.pizza
@vikunja@social.linux.pizza · Feb 09, 2026
🚀 Vikunja 1.1.0 is out! 🔒 Includes a security fix! Also: 🆕 S3 signing config, webhook Basic Auth, smarter date parsing & more fixes. Upgrade highly recommended! https://vikunja.io/changelog/vikunja-v1.1.0-was-released
View on social.linux.pizza
0
1
0
0
313k7r1n3

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • VPN Policy

Email Settings

IMAP: mail.elektrine.com:993

POP3: pop3.elektrine.com:995

SMTP: mail.elektrine.com:465

SSL/TLS required

Support

  • support@elektrine.com
  • Report Security Issue

Connect

Tor Hidden Service

khav7sdajxu6om3arvglevskg2vwuy7luyjcwfwg6xnkd7qtskr2vhad.onion
© 2026 Elektrine. All rights reserved. • Server: 06:52:44 UTC