Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Weston Steimel

@westonsteimel@hachyderm.io
mastodon 4.6.6
  • Open on hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary.

Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

0 Followers
0 Following
18 Posts
Joined November 07, 2022
Codeberg:
https://codeberg.org/westonsteimel
GitHub:
https://github.com/westonsteimel
OpenStreetMap:
https://www.openstreetmap.org/user/westonsteimel

Posts

Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Jul 15, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @darakian@fosstodon.org
@darakian@fosstodon.org @adulau@infosec.exchange @gcve@social.circl.lu Yeah, I get that it is a quite different approach than we have been used to, but I am optimistic it can work. We shall see. I did just add a comment to the proposal around maybe offering a view in future for those that want to trust the community curations that auto-merges them with the 0 GNA records to present a unified CVE view so that all consumers don't have to reimplement that logic. But if a particular consumer disagrees with even that view for a particular record then yeah the solution is to fork to their own namespace with an opposes or equals relationship and then prefer that data in their own feeds. I do understand the concern though, and I know you have a lot of experience with this, so I think we all really appreciate the feedback.
1
1
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Jul 13, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Rather excited about this @gcve@social.circl.lu draft BCP for collaborative community updates to existing CVE records. It feels like it fills a lot of the gaps that the CVE Program has refused to address over the years. Thanks @adulau@infosec.exchange for submitting it! https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110
5
1
2
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Jun 08, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @gcve@social.circl.lu
@gcve@social.circl.lu Is there a way to propose an alias relationship or otherwise merge two separate vendors? For instance in the current dataset we have both "Oracle" and "Oracle Corporation" with some products existing under both, and it would be useful to have some way to unify these.
0
0
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Jun 02, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @westonsteimel@hachyderm.io
@gcve@social.circl.lu This looks great though! As always thanks for building so many great tools in the open!
1
0
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Jun 02, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @gcve@social.circl.lu
@gcve@social.circl.lu Is there a way to propose package url mappings? When I drill down into a product there is a table for PURL mappings, but I'm not seeing a way to propose mappings for that particular section yet.
0
1
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 30, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @westonsteimel@hachyderm.io
And how about actually affordable housing that isn't terrible? And decent community public transport services? Health? Reinstate some railways?
0
0
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 30, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @westonsteimel@hachyderm.io
I do not care about "growth". I care deeply about the future not being a bleak pit of despair. I would much rather investments go towards things with little, no, or even negative return that actively improve the situation for future generations. Things like community owned renewable energy generation, cooperatives, repair cafés, and libraries.
1
1
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 30, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io

I don't suppose anyone has actually managed to find a UK pension fund that actively excludes investment in US tech companies? All of the "ethical" choices still have the same top holdings in Microslop, NVIDIA, Apple, Amazon, Alphabet, and Nazi Corp 🤮

0
2
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 27, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social Yeah, I think I stopped after scanning about 10 GitHub repositories and realised I probably didn't want to know any more.
1
0
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 27, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @sethmlarson@mastodon.social
@sethmlarson@mastodon.social And if you need time to work through all of the findings, consider at least forcing approvals for all external contributors (not just first time) to prevent them from executing
0
0
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 25, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @westonsteimel@hachyderm.io

@whitequark@social.treehouse.systems I managed to rollback fine and then adjusted the publishing processes to use git-pages-cli locally to publish the rendered content rather than pushing to long-lived branches in git. That then allowed me to reupgrade the site to git-pages, and should hopefully also save storage costs for Codeberg since we will now be able to move from three distinct branches storing all of the content to just one (although I've noticed in the past that it seems like garbage collection never runs on the server side or something?). I may look into figuring out CI in the future to avoid the need for long-lived deploy tokens, but this works for now.

I did run into one more issue after the second upgrade which was that some redirects stopped working, but I was able to find from reading the git-pages documentation that I just needed to add ! after the http codes in the _redirects file to force using redirects over any existing route content, and it all started working as expected again.

Thanks again for all of the effort that has gone into this and for the helpful advice

1
2
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 24, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @whitequark@social.treehouse.systems
@whitequark@social.treehouse.systems Thank you! I will give it a try this evening. Really appreciate all of the work you and others are doing here and on ChiPass!
1
2
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 24, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @whitequark@social.treehouse.systems
@whitequark@social.treehouse.systems Yeah, totally understand the reasoning for not supporting git-lfs with git-pages. git-lfs certainly is a pain. I was just using it as I had assumed that it was the least burdensome on Codeberg infrastructure, but it is certainly possible that is an incorrect assumption on my part.
0
2
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 24, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @whitequark@social.treehouse.systems
@whitequark@social.treehouse.systems Oh, seems it doesn't support files stored in git lfs though. I see that mentioned in the git-pages readme, but not in the Codeberg pages migration advice, so might be a good idea to add something there. I can try to figure out where to make a proposal for that this evening. Also, is it possible to roll back to the older server? I may have only discovered all of this after attempting and upgrade (on a test site, but still would like to get it working properly again). Maybe doing a delete of the deployment via cli or something like that?
0
2
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 24, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @andrewnez@mastodon.social
@andrewnez Hmm, so like resources to be strip mined for the profit of a few then?
1
0
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 10, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @westonsteimel@hachyderm.io
@yossarian Do you happen to know if there is already some way to enforce the empty GitHub token permissions block at the workflow level to ensure the scope is only broadened when necessary at the job level? Like a pedantic mode for zizmor excessive-permissions audit or something maybe?
0
1
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Apr 09, 2026
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @yossarian@infosec.exchange
@yossarian This is an excellent write-up. Thanks very much for sharing!
1
1
0
0
Open post
westonsteimel
Weston Steimel @westonsteimel@hachyderm.io · Aug 28, 2025
Weston Steimel
@westonsteimel@hachyderm.io

Software engineer based in the United Kingdom. Seems to know a bit about vulnerability data for some reason. Probably regrets this. Growing increasingly weary. Co-organiser for local #RepairCafe. Attempts to convince people that their "old" devices are still useful beyond the planned obsolescence of Microslop, Amazon, et al.

hachyderm.io
Replying to @joshbressers@infosec.exchange
@joshbressers@infosec.exchange And using the excellent @ecosystems@mastodon.social data for it just serves as a further example of how important many of these single maintainer projects can be.
1
2
0
0

Remote instance

hachyderm.io
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:51:41 UTC