Friendica
daniel:// stenberg://
daniel:// stenberg://

daniel:// stenberg://

bagder@mastodon.social

daniel:// stenberg://

bagder@mastodon.social
I write curl. I don't know anything.
ActivityPub
2023-06-04 08:20:46 2023-06-02 06:48:39 2023-06-02 06:48:37 3347913

daniel:// stenberg://
daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

2 years ago • •

daniel:// stenberg://

2 years ago • •


This #curl Friday graph is the "CVE age in code" one refurbished. I cleaned it up a little and added a median plot to it next to the average. Very similar!

The graph shows all 145 curl CVEs and the number of days each of them existing in shipped source code until fixed.

#curl
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Jimmy Sjölund
mastodon - Link to source

Jimmy Sjölund

in reply to daniel:// stenberg:// • 2 years ago • •
I'm curious, how many days after discovery/reporting?
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Jimmy Sjölund

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Jimmy Sjölund • 2 years ago • •
@jimmysjolund the time from discovery to shipped fix is always very low. Another graph:
@Jimmy Sjölund
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Jimmy Sjölund
mastodon - Link to source

Jimmy Sjölund

in reply to daniel:// stenberg:// • 2 years ago • •
👏
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Lambda
mastodon - Link to source

Lambda

in reply to daniel:// stenberg:// • 2 years ago • •
that's a really good graph! Interesting to see that there are still vulnerabilities being found that have been there since day 1.
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Lambda

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Lambda • 2 years ago • •
@lambda yeah, it's actually quite fascinating I think!
@Lambda
  •  Languages
  •  Search Text
  •  Share via ...
Unknown parent

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

Unknown parent • 2 years ago • •
@krinkle the X axis are all the CVEs and they have not been reported linearly over time
@Timo Tijhof
  •  Languages
  •  Search Text
  •  Share via ...
⇧