I've had to respond to multiple OSS security issues recently and the wild thing is that agents can now generate exploits just on the *rumour* of a bug. This throws security embargoes out the window, as the fix is less important than the knowledge of its existence. What on earth are open source maintainers supposed to do next? https://anil.recoil.org/notes/rumour-is-the-exploit
1
Reply
1
Boost
@avsm working on an ocaml runner profile for you: https://github.com/alpha-omega-security/scrutineer/pull/901