Friendica
daniel:// stenberg://
daniel:// stenberg://

daniel:// stenberg://

bagder@mastodon.social

daniel:// stenberg://

bagder@mastodon.social
I write curl. I don't know anything.
ActivityPub
2025-07-02 15:20:56 2025-07-02 07:39:45 2025-07-02 07:39:44 8143363

daniel:// stenberg://
daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

2 months ago • •

daniel:// stenberg://

2 months ago • •


One of my fav graphs of #curl improvement in recent years, is the one showing vulnerabilities reported separated between low/medium and high/critical.

The report frequency has gone up, but they are less critical these days.

as described
#curl
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to daniel:// stenberg:// • 2 months ago • •

long term improvements is super hard to confirm since the average age a security problem has existed once reported is still around eight years.

So after eight years or so we start to get a picture if we have indeed improved.

  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to daniel:// stenberg:// • 2 months ago • •
that's in particular important to keep in mind when looking at a graph like this, showing the number of known vulnerabilities per 1,000 lines of code in #curl over time:
a plotted line that shrinks over time. At 1.2/1.4 back in the early 2000s, it shrinks pretty linearly towards zero at current date
#curl
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Kal Feher
mastodon - Link to source

Kal Feher

in reply to daniel:// stenberg:// • 2 months ago • •
based on the trend it’ll be negative vulns soon
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Lori Olson
mastodon - Link to source

Lori Olson

in reply to daniel:// stenberg:// • 2 months ago • •
so it you cut it off 8 years back, that’s still an impressive curve
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Peter Bindels
mastodon - Link to source

Peter Bindels

in reply to daniel:// stenberg:// • 2 months ago • •

Can you compare the graph of knowledge over time? IE, if you take now and looking back X years, and compare that to a year ago, looking back X years, does the graph change shape?

If you're improving it should be flatter now (since there were fewer security issues to be fixed).

  •  Languages
  •  Search Text
  •  Share via ...
in reply to Peter Bindels

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Peter Bindels • 2 months ago • •
@dascandy a yes, that's a cool idea. I need to digest that a moment to see if I can make that into a graph somehow...
@Peter Bindels
  •  Languages
  •  Search Text
  •  Share via ...
⇧