https://bugs.gentoo.org/971885 "app-editors/vim: Multiple High risk vulnerabilities in the past few days"
Pfahaha, makes me wonder if it's related to the vibe-code stuff it got in there lately.
https://bugs.gentoo.org/971885 "app-editors/vim: Multiple High risk vulnerabilities in the past few days"
Pfahaha, makes me wonder if it's related to the vibe-code stuff it got in there lately.
@lanodan I don't use vim so not for me to do really, but I'm just waiting for someone to package one of these "boring forks".
From what I saw, at least some of these vulnerabilities (not sure if it's the ones in this bug but wrt the ones going around recently), they got introduced pretty recently and couldn't be repro'd on say Debian stable, so any fork would likely be okay if it's from a little while ago..
@mid_kid @lanodan I do think Vim has always been a bit of a rough situation at least since the huge numbers of CVEs started, because you'd end up being nudged to upgrade quickly and there'd be various regressions.
This just means there's more regressions. It's not uncommon to move more slowly with such upstreams or to stick to an older version.
For this reason, we have (for as long as I've paid any attention to packaging) not rushed to update Vim, often being behind by quite a bit, because of how much broke even pre-LLMs.