We eliminated 1,400 CVEs in NanoClaw's container images
www.echo.ai - 47 poäng - 30 kommentarer - 12741 sekunder sedan
Kommentarer (12)
- prymitive - 3064 sekunder sedanFor those unfamiliar, “CVE” stands for “CV Enrichment”, common slang in Posture Engineering
- halestock - 9819 sekunder sedanPretty impressive to introduce 1400 CVEs in a project that's only ~7 months old.
- tptacek - 3721 sekunder sedanIf you're not a security person, the unspoken subtext here: the overwhelming majority of these "CVEs" do not matter to the project, and a very large number of them don't matter at all. They're pro-forma findings, like ReDOS in code paths that are rarely used, or, even more commonly, "prototype pollution" issues.
- aliasxneo - 7277 sekunder sedanI'm convinced you can tackle 5-10 "CVEs" a day, make a little dashboard, put some pretty graphs on it, and send it to your exec team and probably get accolades. Nevermind that the CVEs had nothing to do with your product.
- eviks - 2011 sekunder sedanWhat is NanoClaw? Glad you asked:
> NanoClaw is a secure, lightweight alternative to OpenClaw.
- sajithdilshan - 2396 sekunder sedanI wonder how many new CVEs were introduced while patching these
- evanjrowley - 5256 sekunder sedanWhy is the Node ecosystem like this? Why do people continue to choose it for popular projects vs. anything else?
- raver1975 - 2573 sekunder sedanThat's what happens when you vibe code.
- iandanforth - 8735 sekunder sedanI don't understand the 'custom patch' strategy over 'fix the app with a major version change' strategy.
- bryan0 - 3147 sekunder sedanWhy hasn't looking at EPSS (Exploit Prediction Scoring System) become a more standard approach than just raw CVEs?
- Surac - 3226 sekunder sedanlet me guess. they wrote a promt that told claude do undo all bugs?
- KaiserPro - 10230 sekunder sedanso s/bookworm/trixie/g didn't work then?
Yes, this is mostly a joke, I am able to understand the difference between base distros.
Nördnytt! 🤓