1 Followers
56 Following
51 Posts

What do you think are the primary challenges for Open Source the coming years?

Security? CRA? Financing? Maintainer burnout? Recruiting young developers? Adapting to a country-former-ally going nuts? AI slop? AI bot overload? Something else?

(I'd like some more food for thoughts for an upcoming talk)

The same thing does *not* happen when I show this slide

Let me introduce you to my new friend #curl 8.11.0

One vulnerability fixed, five changes, 266 bugfixes.

https://daniel.haxx.se/blog/2024/11/06/curl-8-11-0/

curl 8.11.0

curl 8.11.0 is released, featuring one security fix, five changes and 265 bugfixes.

daniel.haxx.se

axum 0.7 is finally out 🚀 #rustlang

Comes with hyper 1.0 support, axum's own Body type, and fewer generics.

https://tokio.rs/blog/2023-11-27-announcing-axum-0-7-0

Announcing axum 0.7.0 | Tokio - An asynchronous Rust runtime

Tokio is a runtime for writing reliable asynchronous applications with Rust. It provides async I/O, networking, scheduling, timers, and more.

Improved Multithreading in wgpu - Arcanization Lands on Trunk - gfx-rs nuts and bolts

Because these billboards are just monitors rotated 90 degrees, they’re invisible to polarized sunglasses. It’s like a real-life ad blocker!

We disclosed this #hackerone report against #curl when someone asked Bard to find a vulnerability, and it hallucinated together something:

https://hackerone.com/reports/2199174

curl disclosed on HackerOne: [Critical] Curl CVE-2023-38545...

## Summary: Curl CVE-2023-38545 vulnerability code changes are disclosed on the internet ## Steps To Reproduce: To replicate the issue, I have searched in the Bard about this vulnerability. It disclosed what this vulnerability is about, code changes made for this fix, who made these changes, commit details etc even though this information is not released yet on the internet. In addition to it,...

HackerOne

Today we got what must be the most alarming first line in a newly file sec issue to #curl:

"To replicate the issue, I have searched in the Bard about this vulnerability"

... followed by a complete AI hallucination where Bard has dreamed up a new issue by combining snippets from several past flaws. Creative, but hardly productive.

Closed as bogus.