36 points torcete 1 hour ago 3 comments
FloatArtifact 59 minutes ago | parent
"
* We have seen a number of cases where a security bug identified
* by AI tools is subsequently independently discovered by a
* different researcher. This suggests that adversaries who do not
* report bugs to OSS projects are likely to be able to discover
* these bugs too. Given this, the OpenSSH team will, for now, be
* making more frequent releases to get bugfixes into users' hands
* more quickly rather than batching them until the next planned
* release."
brynet 8 minutes ago | parent
> sshd(8): On OS X SDK >= 27, sandboxing is no longer supported as the API we depended upon has been removed and no obvious alternative provided.
https://github.com/openssh/openssh-portable/commit/d4b4c304a...
po1nt 1 minute ago | parent
I think this is much healthier approach to AI reports than curl has. But I understand both sides.