tptacek 6 minutes ago

If you're not a security person, the unspoken subtext here: the overwhelming majority of these "CVEs" do not matter to the project, and a very large number of them don't matter at all. They're pro-forma findings, like ReDOS in code paths that are rarely used, or, even more commonly, "prototype pollution" issues.

halestock 1 hour ago

Pretty impressive to introduce 1400 CVEs in a project that's only ~7 months old.

  • devin 1 hour ago

    If the thing measuring whether there are CVEs is also the thing creating said CVEs, are we sure they are even CVEs? Deduped? Etc.

  • GavCo 1 hour ago

    These are CVEs in the base image and in standard lib dependencies. For example, just scanned an unhardened image I built today:

      Unhardened: docker.io/nanoco/nanoclaw:agent-alpha
      71 packages, 344 unique CVEs, linux/arm64
    
      PACKAGE         VERSION        TYP   C   H   M   L   N  TOT
      -----------------------------------------------------------
      expat           2.5.0          deb   0   4  18   1   2   25
      curl            7.88.1         deb   4   4   6   0   7   21
      hono            4.12.14        npm   0   1  18   2   0   21
      libtiff         4.5.0          deb   0   2   1   1  15   20
      perl            5.36.0         deb   5   6   3   0   3   17
      pnpm            10.33.0        npm   0   8   7   0   0   15
      glibc           2.36           deb   1   2   2   1   7   13
      openjpeg        2.5.0          deb   0   0   3   1   9   13
      cups            2.4.2          deb   0   2   8   0   1   11
      glib2           2.74.6         deb   1   7   1   0   1   10
      tar             1.34(+2)       deb   1   1   7   0   1   10
      llvm            15.0.6         deb   0   0   0   1   9   10
      sqlite3         3.40.1         deb   1   2   3   0   3    9
      nss             3.87.1         deb   1   0   3   0   4    8
      avahi           0.8            deb   0   0   8   0   0    8
      util-linux      2.38.1         deb   0   0   3   0   2    7
      elf             0.188          deb   0   0   0   0   7    7
      libssh2         1.10.0         deb   1   4   1   0   0    6
      openldap        2.5.13         deb   0   1   0   0   5    6
      chromium        151.0.7922.108 deb   0   5   0   0   0    5
      -----------------------------------------------------------
      UNIQUE CVEs                         16  68 121  17 119  344
    
      (+51 more packages, 102 findings)
    
      C/H/M/L/N = critical/high/medium/low/negligible.
      Counts are unique CVEs: binaries from one source package are
      grouped (libcurl4 + libcurl3-gnutls + curl = curl), so a CVE
      hitting three of them counts once, not three times.
    • viccis 13 minutes ago

      Are these real findings, or a situation in which fixes have been backported? At one place I worked, the corpsec guys were wildly incompetent and would try to bury me in "CVEs" in my systems that were nothing but "vulnerable" software versions with all of the "identified" vulnerabilities fixed by Debian backported patches.

      • lokar 11 minutes ago

        That’s not security, it’s compliance.

    • concinds 5 minutes ago

      So the model found a fraction of the known vulnerabilities in 2.5 year old curl? Am I getting this right?

  • random3 38 minutes ago

    It’s like it’s made of CVEs. First 50-100 should be a good sign if it’s cleaner to start over.

evanjrowley 32 minutes ago

Why is the Node ecosystem like this? Why do people continue to choose it for popular projects vs. anything else?

  • itintheory 14 minutes ago

    It's the opposite of NIH syndrome. Need to left pad a string? Just import a library from some rando on the internet!

  • ljm 3 minutes ago

    Because, like it or not, it does Write Once, Use Anywhere better than Java ever did.

    It is pretty much the lowest common denominator for code.

aliasxneo 1 hour ago

I'm convinced you can tackle 5-10 "CVEs" a day, make a little dashboard, put some pretty graphs on it, and send it to your exec team and probably get accolades. Nevermind that the CVEs had nothing to do with your product.

  • nathancahill 1 hour ago

    This is how Vanta et al. make millions.

  • lokar 9 minutes ago

    My favorite urgent must fix CVE from compliance was a bug in the Linux PCMCIA driver on some EC2 VMs.

iandanforth 1 hour ago

I don't understand the 'custom patch' strategy over 'fix the app with a major version change' strategy.

KaiserPro 1 hour ago

so s/bookworm/trixie/g didn't work then?

Yes, this is mostly a joke, I am able to understand the difference between base distros.

  • iririririr 28 minutes ago

    a spot on "joke". deb12 is gone for a month now.