Rendered at 23:12:22 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
JamesCoyne 2 hours ago [-]
Really commendable work fixing up the upstream python project. I don't think there's anything to be embarrassed about in the timeline.
arusekk 15 minutes ago [-]
I would prefer to do a super proper disclosure with coordinated release dates and everything. My first submitting to SourceHut security ML ended up making the vuln existence somewhat public before upstream ever knew.
bstsb 54 minutes ago [-]
haven’t been properly rickrolled in years, wasn’t expecting that!
arusekk 15 minutes ago [-]
You're welcome!
serhack_ 2 hours ago [-]
I love sourcehut, and I can't really think anything to replace it. But here's my shot. It's a popular myth that independently from the project size, someone should always take the main stream product in the field than small projects because most of the people would use the main stream product and there's an higher chance that vulnerabilities get already exploited/recognized/fixed. Is that true or not? TL;DR: in the evaluation of such products (sourcehut but even self hosted stuff), should we also take account about the project history and the exposition to threats?
rvz 2 hours ago [-]
HN hug of death, strikes again.
arusekk 13 minutes ago [-]
That might have been DNS, the website itself is on sourcehut pages. Should be fine now for a while.