GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Sunday, 18-Feb-2024 15:56:20 JST Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
    • Kevin Beaumont
    @GossiTheDog Wow, that is a painfully obvious backdoor, really just confirms that nobody reads.
    In conversation about a year ago from queer.hacktivis.me permalink
    • Embed this notice
      craftycat (craftycat@mastodon.scot)'s status on Sunday, 18-Feb-2024 20:05:19 JST craftycat craftycat
      • Kevin Beaumont

      @GossiTheDog This might be a very dumb question, but why on earth are randos allowed to push shit into the project without any review system in place whatsoever? I feel like some extremely basic setting changes would prevent this from happening?

      In conversation about a year ago permalink
    • Embed this notice
      craftycat (craftycat@mastodon.scot)'s status on Monday, 19-Feb-2024 01:19:46 JST craftycat craftycat
      • Kevin Beaumont

      @GossiTheDog That seems like both a gross misunderstanding of what devops is, and a fault entirely caused by whoever set up said software repository. I learned how to avoid this shit within a few months of my first year as a dev student, anyone who's responsible for an opensource repo and doesn't know that is obviously unfit 😂

      In conversation about a year ago permalink
    • Embed this notice
      linuxct (linuxct@androiddev.social)'s status on Monday, 19-Feb-2024 07:31:54 JST linuxct linuxct
      • Kevin Beaumont

      @GossiTheDog How is that related to DevOps though? Secure development lifecycle is the responsibility of the developer who decides to integrate the 3rd party component, not the team who makes it scale up. Or am I missing something?!

      In conversation about a year ago permalink
    • Embed this notice
      linuxct (linuxct@androiddev.social)'s status on Monday, 19-Feb-2024 07:39:39 JST linuxct linuxct
      • Kevin Beaumont

      @GossiTheDog Still, isn't the vulnerability introduced by using a 3rd party component on the source level? My understanding is that the choice of these are up to software developers, and not DevOps...

      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.