I'm convinced you can tackle 5-10 "CVEs" a day, make a little dashboard, put some pretty graphs on it, and send it to your exec team and probably get accolades. Nevermind that the CVEs had nothing to do with your product.
If you're not a security person, the unspoken subtext here: the overwhelming majority of these "CVEs" do not matter to the project, and a very large number of them don't matter at all. They're pro-forma findings, like ReDOS in code paths that are rarely used, or, even more commonly, "prototype pollution" issues.
Discovered a new legit CVE today during a meeting with some other engineers. I’m going to make sure the one who originally brought it up gets to put it on his résumé. The world needs more people like that.
I was intrigued by nano claws more “secure” marketing, but I couldn’t believe how loose and vibe coded the installation and set up process was. My god it’s full of prompts.
18 comments
[ 23.4 ms ] story [ 582 ms ] threadYes, this is mostly a joke, I am able to understand the difference between base distros.
> NanoClaw is a secure, lightweight alternative to OpenClaw.