Friendica
daniel:// stenberg://
daniel:// stenberg://

daniel:// stenberg://

bagder@mastodon.social

daniel:// stenberg://

bagder@mastodon.social
I write curl. I don't know anything.
ActivityPub
2023-06-22 06:23:20 2023-06-21 12:44:08 2023-06-21 12:44:05 3503064

daniel:// stenberg://
daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

2 years ago • •

daniel:// stenberg://

2 years ago • •


Number of announced security vulnerabilities in #curl per year, separated into high/critical vs low/medium.

These are real severity levels, not the NVD spicy versions.

#curl
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Gustav Wengel
mastodon - Link to source

Gustav Wengel

in reply to daniel:// stenberg:// • 2 years ago • •
Damn what happened in 2016?
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Gustav Wengel

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Gustav Wengel • 2 years ago • •
there was a security audit that explains parts of it: daniel.haxx.se/blog/2016/11/23…

curl security audit | daniel.haxx.se

daniel.haxx.se
This entry was edited (2 years ago)
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Gustav Wengel
mastodon - Link to source

Gustav Wengel

in reply to daniel:// stenberg:// • 2 years ago • •
yeah makes sense that would result in a solid spike. Really reassuring to see the amount of high critical vulns go down in the later years though! You're all doing great work
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Gustav Wengel

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Gustav Wengel • 2 years ago • •
@geewee thank you, I too like that fact, but it also required this split in severity to show, because of the increase of low/medium ones lately
@Gustav Wengel
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Gustav Wengel
mastodon - Link to source

Gustav Wengel

in reply to daniel:// stenberg:// • 2 years ago • •
Just shows not all vulnerabilities are born equal!
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Stefan Arentz
mastodon - Link to source

Stefan Arentz

in reply to daniel:// stenberg:// • 2 years ago • •
Would be interesting to see that next to some other metrics like community size or amount of change in the code base.
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Stefan Arentz

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Stefan Arentz • 2 years ago • •
@st3fan hm, let me see what I can do...
@Stefan Arentz
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Stefan Arentz

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Stefan Arentz • 2 years ago • •
@st3fan the issue then becomes that the vulns are counted on report date. It mostly looks messy if I add 12 month average number of LOC changed per month
@Stefan Arentz
  •  Languages
  •  Search Text
  •  Share via ...
⇧