On both your average days and your bad days.
Over the 40 to 50 years that your carer lasts.
I guess those kind of developers exist, but I know that I'm not one of them.
515 karma · joined April 17, 2017
On both your average days and your bad days.
Over the 40 to 50 years that your carer lasts.
I guess those kind of developers exist, but I know that I'm not one of them.
I'm sure that you are perfectly able to do your own research, why are you trying to push that work onto some stranger on the internet?
But it seems like almost no distributions have patched it yet
https://security-tracker.debian.org/tracker/CVE-2025-48386 (debian as an example)
And the security advisory is from yesterday: https://github.com/git/git/security/advisories/GHSA-4v56-3xv...
Did git backdate the release?
In a good and just society there is a large overlap between them, and in others there is less overlap.
But it's impossible to build a legal system where there is a 100% overlap, and it would most likely be a broken society in other ways.
I totally agree with your second paragraph, that the government needs to remove loopholes and other ways for people to weasel out of contributing to society. But there will always be some corruption and a lot of money to be earned by only taking from our shared resources and never contributing back.
It was a strategy that failed in practice and needed to be replaced with a vm based approach.
The Linux kernel have a huge surface area with some subtle behavior in it. There was no economic way to replicate all of that and keep it up to date in a proprietary kernel. Specially as the VM tech is well established and reusable.
I have sent about 50 or so patches upstream for the 300 packages I maintain and while it reduces the amount of work long-term it's also surprisingly amount of work.
Typically the Debian patches are licensed under the same license as the original project. So there is nothing stopping anyone who feels that more patches should be sent upstream to send them.
Typically the Debian maintai
But those tend to be against journalists and activists.
What threat model you operate under is a nontrivial problem.
So you need to approve the usage of that secret by touching the yubikey.
At best it will make the planet prettier and at worst it will simply be feelgood.
But its not obvious that the same is true for a library.
The RustCrypto project breaks each algorithm into its own crate, while botan implrments everything.
Its not obvious to me that one approach is clearly superior to the other.
At least 1 to 10 is my guess.
My understanding is that this would just cause the dangerous things to be repeatable.
But I have a hard time to envision any other solution than "better tooling for refactoring".
Check the green build matrix on this page: https://qa.debian.org/developer.php?login=alexander.kjall%40...
If the most complex thing you can build is a todo-app, then I think you don't produce much value to society.
It should be kept out of regulations.