Get the latest tech news
New era of slop security reports for open source
I'm on the security report triage team for CPython, pip, urllib3, Requests, and a handful of other open source projects. I'm also in a trusted position such that I get "tagged in" to other open sou...
I'm on the security report triage team for CPython, pip, urllib3, Requests, and a handful of other open source projects. Recently I've noticed an uptick in extremely low-quality, spammy, and LLM-hallucinated security reports to open source projects. My alma-mater the University of Minnesota rightfully had its reputation thrown in the trash in 2021 over their experiment to knowingly socially deceive Linux maintainers.
Or read this on Hacker News