Researching Clawhub for a conference talk at the moment.
It’s like they are speed running every package manager security flaw from the past 20 years 😅
Researching Clawhub for a conference talk at the moment.
It’s like they are speed running every package manager security flaw from the past 20 years 😅
Oh fun, if a user gets banned, all their skills are hard deleted...
LEFTPAD.md
Note to self: must stop tooting zero days
This talk started out with a single slide about ClawHub, at this point there's about 3 vulnerability reports I need to make before I can even give the talk :blobsweats:
We've got lockfiles! https://github.com/search?q=path%3A.clawhub%2Flock.json&type=code
(no manifest file to go along with it though)
Definitely not investigation how worm-able clawhub is right now.
<this-is-fine.gif>
Another fun one, ClawHub has an auto-hide feature if enough users report a skill as problematic.
Anyone want to guess how many unique GitHub accounts you would need to completely hide every skill in the registry?
This talk is only 30 minutes, I'm going to speed running this thing too!
*slaps roof*
You can fit so many vulnerabilities in this baby!
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.