Matthias Mair

@matmair
30 Followers
89 Following
418 Posts
Open Source, DevOps and civil engineering.
GHhttps://github.com/matmair
Backuphttps://codeberg.org/matmair
Websitehttps://mjmair.com
@leyrer how nice to spend the day in a all-hands-on-deck incident call just to discover that your security focused migration probably caused the security incident.
Sometimes I ask myself why everything seems to be going downhill everywhere.
@jpm #inventree provides native packages for Debian and has bare metal instructions. What issues are you phasing?

InvenTree 1.2.6 contains fixes for new security advisories

Updating to 1.2.6 is strongly advised. See GHSA-rhc5-7c3r-c769 and GHSA-m8j2-vfmq-p6qg for details.
Every admin should be aware of the assumed trust in our threat model. If you followed it you are not vulnerable see https://docs.inventree.org/en/latest/concepts/threat_model/

many thanks to patelhettt (x2) and alonaki for their research and responsible disclosure

#inventree #inventreedb #opensourcesecurity

Threat Model - InvenTree Documentation

InvenTree - Open Source Inventory Management

@davidism maybe this means OpenAI has understood that its current methods for speeding up developers are far to ressource intensive and they are trying to pivot to rust-build dev tools? /s

„leider muss ich den Termin absagen, da die Thematik außerhalb meines definierten Zuständigkeitsbereiches liegt.“

Leider war das die einzige Person, die sich kümmerte und kompetente Antworten gab.

Willkommen im agilen Konzern.

@IT_Fettchen scheint ein Trend zu sein aktuell, schreibe auch grad viele solche mails
@hynek for sure, I feel the volume of shitty PRs rising weekly.
@hynek imo it just added a few seconds to minutes to recognize that someone has no idea what they are doing / trying to do
As someone who’s been maintaining FOSS projects of various levels of popularity for more than a decade, I need y’all to understand one thing: LLMs didn’t change the median PR quality. (1/6)

Das Zitat ist nicht weniger als ein Rücktrittsgrund. Abgesehen von der Abstrahierung (mehr Risikoexperimente ohne Safeguards, weniger Datenschutz), die Wahnsinn genug ist (vom Staatssekreatär für Digitalisierung!).

Wo bitte kommen wir hin, wenn ein Regierungspolitiker einen Bürger und Bürgerrechtsaktivisten wie Max Schrems persönlich für verzichtbar erklärt?

Q: https://www.diepresse.com/20662631?giftcode=5fe619472b55cac4290e30a2561b20869ee5bf1d