For those unfamiliar, “CVE” stands for “CV Enrichment”, common slang in Posture Engineering
show comments
halestock
Pretty impressive to introduce 1400 CVEs in a project that's only ~7 months old.
show comments
tptacek
If you're not a security person, the unspoken subtext here: the overwhelming majority of these "CVEs" do not matter to the project, and a very large number of them don't matter at all. They're pro-forma findings, like ReDOS in code paths that are rarely used, or, even more commonly, "prototype pollution" issues.
aliasxneo
I'm convinced you can tackle 5-10 "CVEs" a day, make a little dashboard, put some pretty graphs on it, and send it to your exec team and probably get accolades. Nevermind that the CVEs had nothing to do with your product.
show comments
evanjrowley
Why is the Node ecosystem like this? Why do people continue to choose it for popular projects vs. anything else?
show comments
eviks
What is NanoClaw? Glad you asked:
> NanoClaw is a secure, lightweight alternative to OpenClaw.
show comments
sajithdilshan
I wonder how many new CVEs were introduced while patching these
iandanforth
I don't understand the 'custom patch' strategy over 'fix the app with a major version change' strategy.
raver1975
That's what happens when you vibe code.
bryan0
Why hasn't looking at EPSS (Exploit Prediction Scoring System) become a more standard approach than just raw CVEs?
KaiserPro
so s/bookworm/trixie/g didn't work then?
Yes, this is mostly a joke, I am able to understand the difference between base distros.
show comments
Surac
let me guess. they wrote a promt that told claude do undo all bugs?
For those unfamiliar, “CVE” stands for “CV Enrichment”, common slang in Posture Engineering
Pretty impressive to introduce 1400 CVEs in a project that's only ~7 months old.
If you're not a security person, the unspoken subtext here: the overwhelming majority of these "CVEs" do not matter to the project, and a very large number of them don't matter at all. They're pro-forma findings, like ReDOS in code paths that are rarely used, or, even more commonly, "prototype pollution" issues.
I'm convinced you can tackle 5-10 "CVEs" a day, make a little dashboard, put some pretty graphs on it, and send it to your exec team and probably get accolades. Nevermind that the CVEs had nothing to do with your product.
Why is the Node ecosystem like this? Why do people continue to choose it for popular projects vs. anything else?
What is NanoClaw? Glad you asked:
> NanoClaw is a secure, lightweight alternative to OpenClaw.
I wonder how many new CVEs were introduced while patching these
I don't understand the 'custom patch' strategy over 'fix the app with a major version change' strategy.
That's what happens when you vibe code.
Why hasn't looking at EPSS (Exploit Prediction Scoring System) become a more standard approach than just raw CVEs?
so s/bookworm/trixie/g didn't work then?
Yes, this is mostly a joke, I am able to understand the difference between base distros.
let me guess. they wrote a promt that told claude do undo all bugs?