Posts by kpcyrd@chaos.social
 (DIR) Post #B4BdRka7uaC2qRbOnw by kpcyrd@chaos.social
       0 likes, 0 repeats
       
       @jas It looks like there have been rustsec advisories (RUSTSEC-2026-00{23,24,25,26}), but only one of them has a severity of 'high', the other ones have a severity of 'none'.Anybody can send pull requests to the advisory-db, maybe the author of the blogpost could add to them and adjust the impact/severity/description/title.Note also (by @djc):https://github.com/cryspen/libcrux/issues/1335
       
 (DIR) Post #B5njT4Mhs56y1ZKWKu by kpcyrd@chaos.social
       0 likes, 0 repeats
       
       @sam @ariadne @jvoisin as much as I want forgejo to be the good folks, the optics ain't great: https://codeberg.org/forgejo/forgejo/pulls/12288You may ASK unpaid security research volunteers to participate in some coordinated disclosure, but you can't demand they surrender their free time beyond the report. The maintainers are NLnet funded, the security researcher is operating on goodwill. The bugs are still sitting unaddressed in the open, although there's a recent commit fixing token expiry.