Open SourceSimon Willison

Just a rumour of a bug is enough to find a security exploit these days

#security#open-source#ai#ocaml#coding-agents

English

Anil Madhavapeddy reports that security issues in OCaml projects are being exploited within minutes of patches being discussed, highlighting the effectiveness of automated coding agents. This rapid discovery rate raises concerns about the adequacy of existing open source embargo practices for new issues, as evidenced by a significant increase in security disclosures in various projects.

中文

Anil Madhavapeddy 报告称,OCaml 项目的安全问题在补丁讨论后几分钟内就被利用,突显了自动编码工具的有效性。这种快速发现的速度引发了对现有开源新问题禁令实践的担忧,因为各个项目的安全披露数量显著增加。