frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Ask HN: Are other OS maintainers being spammed with Security Vulnerabilities?

3•majora2007•1h ago
I'm being hit with small, nitpick security vulnerabilities, like being able to IDOR profile images for other users on a self-hosted software.

Then the submitters are spamming me to release a vulnerability, despite me messaging stating the next release will trigger the release (there are no release dates for my product, but usually every 3 months).

It's becoming overwhelming. What practices are other maintainers putting in place?

Comments

Guestmodinfo•1h ago
Is it possible to let AI analyze your messages and only show you the ones which don't contain certain keywords like "i will release vulnerability".
majora2007•1h ago
Well these are well written security vulnerabilities with reproduction steps. It's hard to tell if it's an AI discovering or a user using AI to find issues. But suddenly, I'm having an influx of issues where-as for the past 5 years, I received maybe 5. Just this month, I've been hit with 5 low effort vulnerabilities (all very small, unlikely to expose anything of value).

But it's very hard to maintain these in addition to the release work.

samuelknight•19m ago
If it has steps to reproduce, you give it to your coding agent to "fix [bug] using TDD". If it can't make a test it wasn't reproducible.
dubyabee2•1h ago
Yes. It is across most categories of software and services.
mmarian•1h ago
I don't have any big open source projects, but why not just ignore them?
majora2007•1h ago
Because if there are valid ones, they may impact users... It's important to do due diligence (but this takes time to validate them).
mmarian•55m ago
A lot of things seem important in software, but we need to prioritize and compromise based on resources available. Based on what you've said so far, it seems to me that this project isn't giving you enough resources to invest in this particular problem.

That's the attitude I have with my software projects.

The Essays of Michel de Montaigne Online

https://hyperessays.net/
1•floweronthehill•2m ago•0 comments

Rot (Return on Tokens), Product Team Health – Food for Agile Thought #548

https://age-of-product.com/food-agile-thought-548-rot-return-on-tokens/
1•swolpers•3m ago•0 comments

A real-ephemeris 3D universe explorer in the browser

https://space.pointdynamics.com/
1•apprised•3m ago•0 comments

Fossils show ancient primates had grooming claws as well as nails (2018)

https://www.floridamuseum.ufl.edu/science/ancient-primates-had-grooming-claws/
2•maxloh•3m ago•0 comments

Canadian mother sues OpenAI, alleging ChatGPT led her daughter to kill herself

https://www.theguardian.com/technology/2026/jun/11/canada-mother-chatgpt-daughter-suicide-lawsuit
2•Brajeshwar•4m ago•0 comments

F-bombs don't make LLMs smarter

https://tcz.hu/blog/2026/06/12/swearing-and-llms/
2•hntcz•5m ago•0 comments

Long Humans

https://www.thriveholdings.com/long-humans
1•skogstokig•6m ago•0 comments

Show HN: Crowfly.golf – Zero-backend GPS round tracking (localStorage)

https://crowfly.golf
1•whycombinetor•7m ago•0 comments

Think Interior Design Jobs

1•Ai-Dir•8m ago•0 comments

Show HN: AppLaunch - IOS & Android App Builder

https://applaunch.teamzlab.com/
1•mdhemalakhand•8m ago•1 comments

Appeals court upholds FTX co-founder Sam Bankman-Fried's fraud conviction

https://apnews.com/article/sam-bankman-fried-ftx-cryptocurrency-appeal-e709df4a152e9b3b52a266dd81...
2•1vuio0pswjnm7•9m ago•0 comments

IdleAds – Ads in AI's "thinking " moment, devs keep 70%+

https://IdleAds.dev
1•codepeekr•10m ago•1 comments

Agent Control Plane in your database

https://www.exasol.com/blog/exasol-agent-control-plane/
1•exasol_nerd•11m ago•0 comments

UFO footage just released by FBI

https://www.bbc.com/news/videos/c8e2w83kxryo
2•oliver236•12m ago•1 comments

White House negotiating preemption of state AI laws in exchange for KOSA & more

https://thehill.com/policy/technology/5916062-artificial-intelligence-federal-preemption-negotiat...
4•iamnothere•13m ago•1 comments

A calculator that doesn't round

https://constructive-calculator.dimview.org/writeup.html
2•dimview•13m ago•1 comments

Results from First Anthropic Public Record

https://www.anthropic.com/news/anthropic-public-record
1•surprisetalk•16m ago•0 comments

The small web is beautiful

https://benhoyt.com/writings/the-small-web-is-beautiful/
3•otolock•17m ago•0 comments

Closing a Mac remote session without logging out, keeps your Mac logged in [video]

https://www.youtube.com/watch?v=9prKU2Vuo-0
1•whereistejas•17m ago•0 comments

Red Lobster's 37-year-old CEO bets the chain's future on AI

https://moneywise.com/news/top-stories/red-lobster-ceo-damola-adamolekun-ai-anthropic-claude-rest...
2•cdrnsf•17m ago•0 comments

Elon Musk Becomes First Trillionaire as SpaceX Starts Trading

https://www.nytimes.com/live/2026/06/12/business/spacex-ipo-elon-musk/heres-the-latest
5•droidjj•18m ago•0 comments

Israeli tech firm accused of targeting First Minister in election

https://www.bbc.co.uk/news/articles/c77yje7n287o
2•asplake•19m ago•0 comments

MrBeast just hit 500M subscribers – half a billion

https://socialblade.com/youtube/handle/mrbeast
1•etrand_•19m ago•0 comments

The Public Now Backs Nuclear Energy. What Will It Take to Make It Happen?

https://www.wsj.com/business/energy-oil/nuclear-energy-public-support-bb744e6e
1•JumpCrisscross•19m ago•0 comments

Confidence Sets, Confidence Intervals

https://bactra.org/notebooks/confidence-sets.html
1•mattbit•20m ago•0 comments

The World Has Moved On

https://pluralistic.net/2026/06/11/lapsarianism/
6•hn_acker•21m ago•0 comments

Show HN: SharkClean MCP

https://github.com/a-funk/sharkclean-mcp
2•afunk•22m ago•0 comments

Overlooked Pollutants Cause About 15 Percent of Global Warming

https://nautil.us/these-overlooked-pollutants-cause-about-15-percent-of-global-warming-1281914
1•Brajeshwar•23m ago•0 comments

Post-Mortems for Agent Runs

https://blog.tacoda.dev/post-mortems-for-agent-runs-2cceeaf13f2e
1•tacoda•23m ago•0 comments

Fear of the SaaSpocalypse is tormenting techland

https://www.economist.com/business/2026/06/10/fear-of-the-saaspocalypse-is-tormenting-techland
1•1vuio0pswjnm7•24m ago•0 comments