We are at 9 days to the next #curl release and we have only *three* pending CVEs to announce (two low, one medium).
Three is like nothing!
(Mythos says it can't find any more. Zeropath finds no vulnerabilities. Codex security shows an empty list.)
Discussion
We are at 9 days to the next #curl release and we have only *three* pending CVEs to announce (two low, one medium).
Three is like nothing!
(Mythos says it can't find any more. Zeropath finds no vulnerabilities. Codex security shows an empty list.)
@bagder @bert_hubert congrats! So now *all* security bugs are fixed, right? 😁 Is this how it works? 😇 just don’t ship any features afterwords and it‘s perfect! 😆
@bagder And here I am, happy when I make less that 5 spelling errors on a 10 word post...
@bagder Phew, light at the end of the tunnel then. Surprisingly little compared to what oss-fuzz has done to FOSS projects before, but I guess that's because all the easy stuff already got picked up by classic static analysis and fuzzing.
@bagder my friends rave about the Japanese Sakana Fugu model and its ability to find flaws others don’t:
@bagder Any C mistakes in there?
@0xThiebaut one of these three is considered a C mistake (use after free)
I'm under no illusion that the last vulnerability has been found. It just might be that the easy ones are picked now.
@bagder Might be waves when the models find new types of vulnerabilities, then they are discovered all over the place. My guess is that it’s not going to be a common occurrence.
“The last vulnerability” sounds like some old school SciFi title. Like a Twilight Zone episode.
@bagder Sure, but I definitely agree this is a very good sign! Curl is likely a leader where we will see other projects follow if the worst has been had.
@bagder If that's really all these machines can find, then their benefit seems pretty small compared to their social and environmental cost.