working theory: we get fewer vulnerability reports late in the weeks as the researchers have all run out of tokens by now...
@bagder did you see the new privacy policy too?

@bagder

I bet they are using their AI's to Min Max their token budgets 😉

@bagder

alternative hypothesis: (more or less) all the vulnerabilities that *could* be found with these tools have been found.

@quincy
Did that stopped them before?

As in if slop-researchers can generate bogus reports what's stopping them from generating more?

The inconsistency of extrusions almost guarantees no duplicates.

@bagder

@bagder ROFL ....Daniel .....these monkeys have no fucking clue what they are doing....believe me ....difficult to stand ...

Anyway kudos to ya for standing those monkeys.

@bagder Presumably that's when the "real" vuln reports pop up since real people have been scratching their heads for a few days and finally understand what's going on.
@grumpydad I'm not convinced those people still exist...
@bagder Now there's a dreary thought...
@bagder Some of us have probably run out of spoons by this point in the week. It’s only Thursday and I am tired already.
@bagder
Ouch! 😂
I'm hoping at least a few of them aren't vibe-researchers.
@bagder I actually bwahahaha'd reading this.
@bagder
Most that I know with token limits get them as a monthly allotment. So at the end of the month they make sure to blow their remaining tokens.
@bagder complimentary theory: the steam runs out of the agent wrangling by the ai folks come Thursday and Friday. Monday they ride again, charged up. 🤷‍♀️ 🛡️
@bagder life was so much better when other actual developers read our open source code...
@bagder You could create a graph of this if you have security vulnerability report information prior to 2023 ;) I suspect this effect may have partially existed before LLMs.
@sethmlarson I suspect that before early 2026 something we had too few reports to see any clear pattern on a day-to-day basis...

@bagder I’m more surprised that the reports keep coming in. Assuming a similar percentage of them are true vulnerabilities.

(Surprised as in impressed.)

@bagder How many vulnerabilities do you believe exist in curl right now, approximately? Its source code is finite, so the amount of vulnerabilities must be as well.
Approaching zero bugs?

In this era of powerful tools to find software bugs, we now see tools find a lot of problems at a high speed. This causes problems for developers, as dealing with the growing list of issues is hard. It may take a longer time to address the problems than to find them - not to … Continue reading Approaching zero bugs? →

daniel.haxx.se
@bagder
I lol'd as my non-IT patents looked at me and for a moment I had the chill of explaining all of this xD