Friendica
daniel:// stenberg://
daniel:// stenberg://

daniel:// stenberg://

bagder@mastodon.social

daniel:// stenberg://

bagder@mastodon.social
I write curl. I don't know anything.
ActivityPub
2024-02-09 10:22:42 2024-02-08 11:32:54 2024-02-08 11:32:50 4497062

daniel:// stenberg://
daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

1 year ago • •

daniel:// stenberg://

1 year ago • •


lines of code per known vulnerability in #curl, 1998 - 2023. I purposely leave out the last year simply because it is a little too new code there to be fair - and that makes the graph really spike.

Note also that this treats all vulns equal, no matter which severity

#curl
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to daniel:// stenberg:// • 1 year ago • •
the median age a CVE has existed in code when reported in #curl is 7.7 years!
#curl
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

robinm
mastodon - Link to source

robinm

in reply to daniel:// stenberg:// • 1 year ago • •
Does this means that we should ignore the right part of the graph (2015 and newer), and wait to see if the quality did effectively increase so much in recent years?
  •  Languages
  •  Search Text
  •  Share via ...
in reply to robinm

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to robinm • 1 year ago • •
@robinm it certainly might imply that we will get vulnerabilities reported for that period in the coming years, yes. I guess we will be able to tell in the future...
@robinm
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Howard Chu @ Symas
mastodon - Link to source

Howard Chu @ Symas

in reply to daniel:// stenberg:// • 1 year ago • •
I think the opposite, vulns per LOC, would be more informative.
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Howard Chu @ Symas

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Howard Chu @ Symas • 1 year ago • •
@hyc It becomes such a hard to grasp number. Like 0.000112 in late 2022.
@Howard Chu @ Symas
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Howard Chu @ Symas
mastodon - Link to source

Howard Chu @ Symas

in reply to daniel:// stenberg:// • 1 year ago • •
hmm, yeah. Ok, use KLOCs, and a log axis
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Howard Chu @ Symas

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Howard Chu @ Symas • 1 year ago • •
@hyc Not bad: The number of vulns per kloc at 1.77 in 1998 and crawls down to 0.112 in late 2022. Still linear yaxis.
@Howard Chu @ Symas
  •  Languages
  •  Search Text
  •  Share via ...

daniel:// stenberg:// reshared this.

in reply to daniel:// stenberg://

stof
mastodon - Link to source

stof

in reply to daniel:// stenberg:// • 1 year ago • •
@hyc the label of the vertical axis is not the right one anymore
@Howard Chu @ Symas
  •  Languages
  •  Search Text
  •  Share via ...
⇧