Seems like he’s been pushed into using LLMs as a way to cope with the deluge of LLM-generated security reports.

  • exu@feditown.com
    link
    fedilink
    English
    arrow-up
    8
    ·
    2 hours ago

    He makes some fair points. However I do think the large amount of regressions in 3.4.3 should have resulted in a new release rolling back those changes.

    I still like the response of the libxml2 maintainer, where any vulnerability will be disclosed openly and fixed when it’s ready. Maybe more open source projects currently drowning in CVE should take that stance instead of their maintainers burning themselves out over it.