263

Seems like he's been pushed into using LLMs as a way to cope with the deluge of LLM-generated security reports.

you are viewing a single comment's thread
view the rest of the comments
[-] exu@feditown.com 45 points 4 days ago

He makes some fair points. However I do think the large amount of regressions in 3.4.3 should have resulted in a new release rolling back those changes.

I still like the response of the libxml2 maintainer, where any vulnerability will be disclosed openly and fixed when it's ready. Maybe more open source projects currently drowning in CVE should take that stance instead of their maintainers burning themselves out over it.

this post was submitted on 03 Jun 2026
263 points (96.8% liked)

Programming

27173 readers
354 users here now

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you're posting long videos try to add in some form of tldr for those who don't want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



founded 3 years ago
MODERATORS