Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Why hasn't looking at EPSS (Exploit Prediction Scoring System) become a more standard approach than just raw CVEs?by bryan0
- I wonder how many new CVEs were introduced while patching these
- I was intrigued by nano claws more “secure” marketing, but I couldn’t believe how loose and vibe coded the installation and set up process was. My god it’s full of prompts.by pokstad
- What is NanoClaw? Glad you asked:
> NanoClaw is a secure, lightweight alternative to OpenClaw.
by eviks - I'm pretty skeptical you can call any claw-like thing secure unless you solve prompt injection.by overgard
- If the lightweight alternative has 1400 CVEs, how many does OpenClaw have?by Hamuko
- That's what happens when you vibe code.by raver1975
- so s/bookworm/trixie/g didn't work then?
Yes, this is mostly a joke, I am able to understand the difference between base distros.
by KaiserPro - a spot on "joke". deb12 is gone for a month now.by iririririr
- I don't understand the 'custom patch' strategy over 'fix the app with a major version change' strategy.by iandanforth
- Why is the Node ecosystem like this? Why do people continue to choose it for popular projects vs. anything else?by evanjrowley
- Primarily because of the original sin of JS being an awfully designed language. Partially because it's the most popular.by eviks
- Because it's written by a type of dev that thinks everything should use JS because that's what they used for 6 months while working at a FAANG company before getting laid off and since they worked at a FAANG company clearly they know better than you so if you attack them for using an extremely poor language you just aren't a seriously person so please shut up while I go fishing for some VC funds.
It's like asking why Claude Code is written with react, because the devs getting paid >$500k a year clearly know better d'uh.
by shimman - Because, like it or not, it does Write Once, Use Anywhere better than Java ever did.
It is pretty much the lowest common denominator for code.
by ljm - Because it's written in Javascript and there are classes of highly-situational and not-especially-meaningful vulnerabilities that broadly impact the entire ecosystem ("prototype pollution" is the canonical example) that get counted individually in every occurrence in every NPM package.
It's not a real number, and, worse, it obscures the real figure of merit (/demerit). The Node ecosystem does have a real problem with its culture of sprawling dependencies. But it's not the first-order issue with this "1400" number.
by tptacek - It's the opposite of NIH syndrome. Need to left pad a string? Just import a library from some rando on the internet!by itintheory
- I'm convinced you can tackle 5-10 "CVEs" a day, make a little dashboard, put some pretty graphs on it, and send it to your exec team and probably get accolades. Nevermind that the CVEs had nothing to do with your product.by aliasxneo
- This is how Vanta et al. make millions.by nathancahill
- My favorite urgent must fix CVE from compliance was a bug in the Linux PCMCIA driver on some EC2 VMs.by lokar
- If you're not a security person, the unspoken subtext here: the overwhelming majority of these "CVEs" do not matter to the project, and a very large number of them don't matter at all. They're pro-forma findings, like ReDOS in code paths that are rarely used, or, even more commonly, "prototype pollution" issues.by tptacek
- So they do matter, just unlikely to be executed.by doc_ick
- For those unfamiliar, “CVE” stands for “CV Enrichment”, common slang in Posture Engineeringby prymitive
- Discovered a new legit CVE today during a meeting with some other engineers. I’m going to make sure the one who originally brought it up gets to put it on his résumé. The world needs more people like that.by evanjrowley
- Common Vulnerabilities and Exposures
https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exp...
by bedros - Pretty impressive to introduce 1400 CVEs in a project that's only ~7 months old.by halestock
- It’s like it’s made of CVEs. First 50-100 should be a good sign if it’s cleaner to start over.by random3
- Hold my beer
- If the thing measuring whether there are CVEs is also the thing creating said CVEs, are we sure they are even CVEs? Deduped? Etc.by devin
- These are CVEs in the base image and in standard lib dependencies. For example, just scanned an unhardened image I built today:
Unhardened: docker.io/nanoco/nanoclaw:agent-alpha 71 packages, 344 unique CVEs, linux/arm64 PACKAGE VERSION TYP C H M L N TOT ----------------------------------------------------------- expat 2.5.0 deb 0 4 18 1 2 25 curl 7.88.1 deb 4 4 6 0 7 21 hono 4.12.14 npm 0 1 18 2 0 21 libtiff 4.5.0 deb 0 2 1 1 15 20 perl 5.36.0 deb 5 6 3 0 3 17 pnpm 10.33.0 npm 0 8 7 0 0 15 glibc 2.36 deb 1 2 2 1 7 13 openjpeg 2.5.0 deb 0 0 3 1 9 13 cups 2.4.2 deb 0 2 8 0 1 11 glib2 2.74.6 deb 1 7 1 0 1 10 tar 1.34(+2) deb 1 1 7 0 1 10 llvm 15.0.6 deb 0 0 0 1 9 10 sqlite3 3.40.1 deb 1 2 3 0 3 9 nss 3.87.1 deb 1 0 3 0 4 8 avahi 0.8 deb 0 0 8 0 0 8 util-linux 2.38.1 deb 0 0 3 0 2 7 elf 0.188 deb 0 0 0 0 7 7 libssh2 1.10.0 deb 1 4 1 0 0 6 openldap 2.5.13 deb 0 1 0 0 5 6 chromium 151.0.7922.108 deb 0 5 0 0 0 5 ----------------------------------------------------------- UNIQUE CVEs 16 68 121 17 119 344 (+51 more packages, 102 findings) C/H/M/L/N = critical/high/medium/low/negligible. Counts are unique CVEs: binaries from one source package are grouped (libcurl4 + libcurl3-gnutls + curl = curl), so a CVE hitting three of them counts once, not three times.by GavCo