GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    AndresFreundTec (andresfreundtec@mastodon.social)'s status on Thursday, 04-Apr-2024 01:55:32 JST AndresFreundTec AndresFreundTec

    I am a bit concerned by all the focus on small-ish projects with overwhelmed maintainers. There indeed are a lot of problems in that area.

    But I am certain that lots of experienced OSS devs can think of a few large and crucial projects where they fairly easily could have hidden something small in a larger change. Without a lot of prior contributions to the project.

    In conversation about a year ago from mastodon.social permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 04-Apr-2024 01:55:32 JST Kevin Beaumont Kevin Beaumont
      in reply to

      @AndresFreundTec yeah. I’m surprised there isn’t more focus on compression libraries and code in tar files, too. There’s specific areas which are risky, but a lot of discussion revolves around ‘this is unmanageable’ before anybody has tried to, er, manage it.

      In conversation about a year ago permalink
    • Embed this notice
      AndresFreundTec (andresfreundtec@mastodon.social)'s status on Thursday, 04-Apr-2024 03:34:26 JST AndresFreundTec AndresFreundTec
      in reply to
      • Kevin Beaumont

      @GossiTheDog I think there are a few people looking into that.

      If I were the team behind "jia", I'd have looked at getting into dissimilar projects, not the same project multiple times, not multiple compression libs. But of course there are other actors...

      The scariest areas I can think of are, in that order, compilers / binutils, buildsystems, "build executors" like make/ninja.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 04-Apr-2024 03:34:26 JST Kevin Beaumont Kevin Beaumont
      in reply to

      @AndresFreundTec there's definitely some people looking at it, but I don't think it's had as much debate as I imagined (e.g. the tar files thing).

      And yeah, there's definitely other areas of attack. But part of me thinks even the known-knowns haven't been exhaustively looked at.

      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.