Quentin Kaiser retweetledi

Upstream's covering up of security information they're aware of at time of commit is directly related to why your distros have no fixes for the copy.fail vuln. Completely irresponsible.
English
Quentin Kaiser
2.6K posts

@qkaiser
Offensive (embedded) security @onekey_sec / @konkretesec founder / @ecoswtf initiator







For my friends who are still using UV and might be a little weary about recent compromises to PyPi packages, stick this in your pyproject.toml. You can let all of those pip users find and report the compromises...


We @binarly_io just open-sourced our VulHunt framework at @REverseConf! GitHub: github.com/vulhunt-re/vul… Documentation: vulhunt.re/docs Slack: join.slack.com/t/vulhunt/shar… vulhunt.re
