https://bugs.gentoo.org/971885 "app-editors/vim: Multiple High risk vulnerabilities in the past few days"

Pfahaha, makes me wonder if it's related to the vibe-code stuff it got in there lately.

971885 – app-editors/vim: Multiple High risk vulnerabilities in the past few days

@lanodan I don't use vim so not for me to do really, but I'm just waiting for someone to package one of these "boring forks".

From what I saw, at least some of these vulnerabilities (not sure if it's the ones in this bug but wrt the ones going around recently), they got introduced pretty recently and couldn't be repro'd on say Debian stable, so any fork would likely be okay if it's from a little while ago..

@thesamesam Well I don't use it either (I use app-editors/vis) so it's kind of me being on the peanut gallery, otherwise pretty sure I probably would have packaged one of those boring forks already.
@lanodan Had a feeling. I feel like editors are one of those where you need someone who actually daily drives it to be sensitive to the various things that can go wrong, tweaked upstream defaults, blah blah
@thesamesam @lanodan I am a heavy user of vim, but have never poked much at its internals (or bothered learning vimscript) so I've yet to notice any of this ensloppification.
Looking around, it seems that too much of the software I rely on has started using AI overnight, making it unavoidable. Drew even has a blog post on replacing rsync with tar due to this, something I really don't see being anywhere near equivalent.
As someone who consistently fights losing fights, this doesn't seem worth it.
@mid_kid @thesamesam Yeah, for rsync I'm so tied to the protocol for uses cases like fetching mirrors that I'll probably give openrsync a shot for replacing it unless a fork appears in the meantime.
@mid_kid @thesamesam Plus well part of the problem is how the forks/re-implementations you can find don't always have an anti-LLM policy.
Add that to how there's quite few pieces of software we probably consider essential (like @system set stuff in Gentoo or BSD base, I think rsync goes in there) that either have got already slopified or nearby software has.