10 Followers
30 Following
353 Posts

Three years ago I blogged about #nuget serving outdated #curl packages.

They then removed the packages I found.

I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

The curl nuget story

Recently there has been an interesting debate in the Open Source world where people have objected to being called "Suppliers" as in Supply Chain Security when you are but an Open Source developer offering your code to the world for free and at no cost but also without any warranties. That is not a supplier, … Continue reading The curl nuget story →

daniel.haxx.se
How an IRC bot spawned the world’s most prolific software

YouTube

@MLE_online yeah, you have to always be logged on, if not, the price is never right.

Also they push a lot to the bundles, sometime you click to add one item to your basket and it redirects to the bundles, and that is a annoying, have to identify what are the bundles to avoid clicking...

But, they are so cheap, and they have so many things that is unavoidable at this time

@jerry first time a promotion means "less money"

@jerry I'm enjoying it, too much lens flare, and it's not Lower Decks, but I like the approach of we are not who we were, we need to reinstate the alliances and we are trying to be better etc.

I don't see they doing it for a lot of seasons, but fro the moment it's ok

@MLE_online "but, but other times if fixed itself!!"

Probably because you called the landlord those times :P

@jerry in my 18s son birthday he blew the candles and then I said.. "so... at what time are you leaving then?"

Of course was a joke... or was it? :D

@MLE_online The perfect organism
@scalzi they should keep trying... never lose hope xD
@jerry I fell your meesage needs more capitalized words to make the full effect,