Advertisement · 728 × 90

Posts by Matt "msw" Wilson

Screenshot showing Inbox, Saved, and Done labels from Github. There's a 1 in a circle

Screenshot showing Inbox, Saved, and Done labels from Github. There's a 1 in a circle

Fun fact: when you have more than 1,000 notices on GitHub, it says you have 1.

It should be like tabs in Chrome on mobile devices, where past 100 it shows ":)"

3 weeks ago 5 0 1 0
Preview
Dealing with the rate of change in software development I am primarily a .NET developer, and in that sphere alone there are at any given time probably close to a dozen fascinating emerging technologies, some of them real game-changers, that I would love...

"Dealing with the rate of change in software development"

Asked 17 years, 6 months ago.

If only I had a time machine to suggest to folks that they try to enjoy the "good 'ole days".
stackoverflow.com/questions/10...

1 month ago 3 2 0 0
Linux Foundation Announces 12.5 Million in Grant Funding to Advance Open Source Security

Linux Foundation Announces 12.5 Million in Grant Funding to Advance Open Source Security

The Linux Foundation Announces $12.5 Million in Grant Funding (via Alpha-Omega and OpenSSF)

Anthropic, AmazonWebServices (AWS), GitHub, Google, GoogleDeepMind, Microsoft, OpenAI to Invest in Sustainable Security Solutions for #OpenSource

openssf.org/press-releas...

1 month ago 7 3 0 1

Some folks in and around Free and Open Source Software (FOSS) are asking, "does AI change everything?"

If you think that FOSS only exists because software is expensive to write, reuse is efficiency, and AI shifts the economics ("we rewrote Next.js in a week with AI!"), you may be worried.

I'm not.

1 month ago 8 0 2 0

I added a sentence to the #curl hackerone submission page:

"Please present your case briefly and to the point. Do not use an AI to help you blab hundreds of line that will exhaust us to death instead of making us understand your claim."

3 months ago 11 2 0 0
Preview
China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) | Amazon Web Services Within hours of the public disclosure of CVE-2025-55182 (React2Shell) on December 3, 2025, Amazon threat intelligence teams observed active exploitation attempts by multiple China state-nexus threat g...

China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182)

aws.amazon.com/blogs/securi...

4 months ago 1 0 0 0
Preview
Node.js EOL Versions CVE Dubbed the "Worst CVE of the Year" ... Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.

Throwback Thursday...

socket.dev/blog/node-js...

4 months ago 1 0 0 0
Preview
Node.js — Updates on CVE for End-of-Life Versions Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

These were the rules when the original plan was made to issue CVEs merely because Node.js versions were EOL. This outcome was easy to predict...

nodejs.org/en/blog/vuln...

4 months ago 0 0 1 0
Advertisement

Why? Because

4.1.13 The state of a Product being EOL, by itself, MUST NOT be determined to be a Vulnerability.

www.cve.org/resourcessup....

4 months ago 0 0 1 0
Preview
Node.js — Tuesday, January 21, 2025 Security Releases Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

Vendored deps are not unusual at all...

But, unfortunately, misuse of the CVE program is all too common in the NodeJS community.

Let's take CVE-2025-23087, CVE-2025-23088, and CVE-2025-23089 for example. All of these CVEs are REJECTED. nodejs.org/en/blog/vuln...

4 months ago 0 0 1 0
React2Shell (CVE-2025-55182)

> The decision to publish a second CVE for Next.js was made due to these exceptional circumstsances: Next.js does not include React as a traditional dependency - instead, they bundle it "vendored"

react2shell.com

4 months ago 0 0 1 0

There are definitely PoCs circulating…

4 months ago 0 0 0 0

Unpopular opinion: a vulnerability that was disclosed privately by researchers and had a coordinated response from vendors and service operators under an (albeit short) embargo is not a “0-day”.

4 months ago 7 0 0 0

4.1.12 The act of updating Product dependencies MUST NOT be determined to be a Vulnerability, regardless of whether the dependencies have Vulnerabilities.

www.cve.org/resourcessup...

4 months ago 0 0 1 0

A public service announcement regarding CVEs: one identified vulnerability gets one CVE.

Each vendor doesn't get their own CVE that corresponds to their security bulletin.

CVE-2025-66478 is REJECTED as duplicate of CVE-2025-55182
www.cve.org/CVERecord?id...

4 months ago 3 0 2 0
Not overselling #aideveloper and #devtools as magical at #aws with Ali Maaz & Jessie VanderVeen
Not overselling #aideveloper and #devtools as magical at #aws with Ali Maaz & Jessie VanderVeen YouTube video by RedMonk

To celebrate #awsreinvent, @redmonk.com has been publishing New Builders conversations w @awscloud.bsky.social leaders every day this week & TODAY IS MY DAY 🎉🎉🎉!! Hear AWS's Ali Maaz & Jessie VanderVeen chat all things #AI & #DevTools w me redmonk.com/videos/insid... www.youtube.com/shorts/Ot0gy...

4 months ago 10 1 0 0
Advertisement

Unpopular opinion: through an economics lens, the optimal number of CVEs in most software systems is almost never 0.

5 months ago 5 0 1 0

Culture eats AI adoption strategy for breakfast, lunch, and dinner.

5 months ago 3 0 0 0

"Our only modification part is that, if the Software (or any derivative works thereof) is used for any of your commercial products or services that have more than 100 million monthly active users, or more than $20M in monthly revenue, you shall prominently display 'Kimi K2' on the user interface"

5 months ago 2 1 1 0

I mean, honesty is a human trait. The humans who built that particular AI system biased the set of mysterious numbers (through reinforcement, filtering, etc.) so it assembles tokens in a way that conveys information about the properties and limitations of the system they built.

That's all.

5 months ago 1 0 0 0
The sun rises at the horizon, reflecting of the water of Eagle Harbor. The car deck of the Washington State ferry Tacoma is in the foreground.

The sun rises at the horizon, reflecting of the water of Eagle Harbor. The car deck of the Washington State ferry Tacoma is in the foreground.

#FerryLife #WAWX #Seattle #Sunrise

5 months ago 12 2 0 0
Preview
Strengthening Liquibase Community for the Future Liquibase Community now uses the Functional Source License (FSL). Learn what this means for developers, contributors, and enterprises, and how it protects sustainability.

"As adoption has grown, so has our responsibility to ensure the project remains sustainable and continues to thrive. That’s why, with the release of Liquibase 5.0, we are updating the license for Liquibase Community."

www.liquibase.com/blog/liquiba...

6 months ago 1 0 2 0
The Tyranny of Metrics: Muller, Jerry Z.: 9780691191911: Amazon.com: Books Buy The Tyranny of Metrics on Amazon.com ✓ FREE SHIPPING on qualified orders

Metrics are increasingly employed as trust deteriorates. Recommended reading ⬇️

#monktoberfest

a.co/d/im8AStV

6 months ago 6 3 0 0
Advertisement
Preview
Coming to a New Awareness of Organizational Culture

Ref: Edgar H. Schein sloanreview.mit.edu/article/comi...

#monktoberfest

6 months ago 0 0 0 0

“Organizational culture is the pattern of basic assumptions that a given group has invented, discovered, or developed in learning to cope with its problems […], and that has worked well enough to be considered valid, and, therefore, to be taught to new members.”
The stories we tell are how we teach.

6 months ago 0 0 1 0

"apparently web traffic is down because Google is giving you an answer already in the results, and you no longer have the need to visit a website"

I mean, this has been a complaint for a while, even before AI entered the timeline? Who needs to go to a music lyrics website when it's in the Info Box?

7 months ago 0 0 0 0

"Piracy lost, but it was always going to lose. Streaming won."

But did the reader / listener / viewer win?

And did the content creators win?

🤔

7 months ago 2 0 1 0

PSA: attacks on public infrastructure like software package registries are on the rise. Here’s an active one targeting folks who have crates.io accounts.

7 months ago 4 3 1 0

I am happily paying Nabu Casa for Home Assistant Cloud.

7 months ago 2 0 0 0

And in the words of @booch.com “Every line of code represents a moral decision"

7 months ago 3 1 0 0