Posts
375
Following
96
Followers
4355
@n0toose @bagder @hughsie @Stephanie Of course, public fixes for public bugs is the huge percentage (like 99%) of all of our security fixes that end up getting accepted and later assigned a CVE.
1
0
1
repeated

@jbm The backlash against Linux kernel advisories is confusing. We wanted transparency; now we have it. More data is always better than a black box. If the new influx of CVEs is breaking your vulnerability management workflow, the problem might be your process, not the advisories.

Thanks for the hard work @gregkh

@bagder

1
3
1
repeated

Thorsten Leemhuis (acct. 1/4)

The support in the is now officially a first class citizen and not considered experimental any more:

https://git.kernel.org/torvalds/c/9fa7153c31a3e5fe578b83d23bc9f185fde115da; for more details, see also: https://lwn.net/Articles/1050174/

This is one of the highlights from the main for 7.0 that was merged a few hours ago ; for others, see https://git.kernel.org/torvalds/c/a9aabb3b839aba094ed80861054993785c61462c

2
17
1
@bagder @hughsie @Stephanie @sethmlarson I second this, @hugsie, you should become a CNA for fwupd. The application process is relatively painless (sit through a presentation, fill out some sample CVEs to prove you know what you are doing, and submit a few testing CVEs to show you know how the tools work).

The OpenSSF guide is great, and a huge shoutout to Python for paving the way for us all to be able to do this.
1
3
8
@hughsie @bagder @Stephanie If you want a CVE for your CV, come fix a Linux kernel bug! We are giving out 13 CVEs a day, plenty to go around for everyone! :)
2
22
67
@jbm @adulau @bagder No, we can't do this for kernel config options, which is why we give you a list of files affected. You know what files you build, so filter on that.

CPE doesn't work to attempt to describe a kernel configuration option as that is not what it was designed for. It was an attempt to make a machine-readable version/program definition, and even then, it does not work well anymore. PURL is the hope for the way out of that mess, and based on my conversations with the PURL developers at FOSDEM, there is hope that it will "soon" work for all open source software packages (right now it does not, so the kernel can not use it.)
0
0
4
repeated

The 2nd Annual have come to a close, but you can still revisit the best moments of the Awards Ceremony.

👇Watch the recording available here :
https://awards.europeanopensource.academy/awards/2026-recording-event

1
2
0
repeated

The European Open Source Awards ceremony from January 29th, in one loooong recording with yours truly showing up several times.

Most blabbing at 1h24 and onward when @gregkh was up.

https://youtu.be/KXS5KQjWjns?si=bN35SofySbhbtys_&t=150

2
1
0
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

I am losing it at how many of my peers have forgotten what software engineering is. It is not typing in lines of code.

4
11
0
repeated

Since we’re not superstitious, the 13th edition of KR will take place September 21–23, 2026 (black cats strictly forbidden during this edition — even on a leash… 😄). We hope to see loads of you there!

And because we want to keep offering the best possible conditions for three days of good vibes and community for everyone, feel free to support this edition by becoming a sponsor. All the info is here!

https://kernel-recipes.org/en/2026/sponsor/

0
8
2
repeated

reading vibecoders talk about how great vibecoding is for engineering real things is like reading bitcoiners talk about how they think money works

4
15
0
repeated
Edited 6 days ago

Being on Team Words Mean Things is difficult these days, particularly when multibillion-dollar companies put out breathless press releases saying "By using our massive language model, whose training data includes every version of GCC ever released, and having it autocorrect its own output by testing it against GCC, we managed to make a C compiler that mostly works for only $20,000 in a week and gosh I have so many feelings."

I mean, what the fuck are we even doing here.

https://www.anthropic.com/engineering/building-c-compiler

7
10
3
repeated

I think it's interesting how software engineers are (among?) the most eager working class group to replace themselves with LLMs.

It's interesting because LLMs do a worse job than us, we lose ability/skill to do our job the more we use it, lose our jobs, produce worse software, are less satisfied with our work, etc.

Yet so many of my peers seem to be super excited about and advocate for it, while other working class groups at least detest LLMs if not even consider organising themselves to protect their trade/jobs from LLMs.

Are we becoming the cops (read as: class traitors) of this techno-fascist dystopia?

6
11
1
@lain I wish I was hallucinating this timeline, that would make me much happier as I would know I could just sober up and it would all be over.
0
0
4
Curiosity got the best of me, and I clicked on the links and this just looks like an OpenAI "sales funnel", which is pretty hilarious when you consider the target was open source security teams, none of which could ever fill out these types of forms without flat out lying.
5
6
32
Looks like the AI companies have finally run out of money as they are asking various open source projects to test their closed source products for them for free. What could go wrong with giving access to an unknown tool to private code repos?

If I didn't know better, I would think this is an elaborate phishing scam, or they have run out of data to scrape and need more training material.

Gotta admire their brazenness...
8
65
92
@larsmb crazy, it has been a long time! And thanks for the kind remarks, from you and everyone else!
0
0
1
As it came up in a few conversations during "FOSDEM week", here's a link to the OpenSSF blog post about why the idea of "attestation for open source projects" is, in my opinion, and others, a bad idea:

https://openssf.org/blog/2026/01/21/preserving-open-source-sustainability-while-advancing-cybersecurity-compliance/

Yes, FOSS foundations and projects need ways of getting funding, that is very important, but thinking that "attestation is how we will get that money!" might not be such a good idea given the risks involved, and the past experience for those that have attempted it.
0
24
36
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

so I like to make plaintext outlines of presentations I do. Today is a banger.

2
4
1
repeated

I may regret this at some point, but I felt the need to put down in writing how I feel about this moment in the tech industry.

It is not kind. You may well be insulted by it. If you are... then you really should question yourself.

https://www.garfieldtech.com/blog/selfish-ai

5
18
2
Show older