Not a software dev but I have heard at least 1 engineer say this in conversation unprompted by Claude. I supposed it’s possible he started using it more after using Claude, but I doubt it.
May be more common in some spaces (like enterprises) than others
Sunday salmon and steak! Steak was a touch overdone but still good. Smoked over cherry and finished in butter, garlic, and rosemary. Chard from the garden stir fried with ginger, garlic, soy sauce, rice wine vinegar, and sesame oil. Chard and summer squash were the first good batch of veggies from the garden! #foodstr
Sure thing! It looked like most findings around implementation were already identified with know fixes as you mention. The things that are new are likely more supply chain improvement and repo hygiene related
@Keith Mukai I built a security audit skill for Claude a while back that tries to establish a strong security system for software based on the documented claims. I pointed it at seedsigner this morning to see what it would do. It’s relatively opinionated and there are pieces like a CI/CD check for audit on each release that might be overkill, BUT I think it flagged some interesting things. It also drafted a SECURITY.md. Posted it as a draft PR in my fork so I could share.
Key suggestions: - one instance of a potential string injection - suggests to pin dependencies to hashes instead of versions to decrease supply chain risk - establishes a SECURITY.md with clear claims
How ironic is it that ColdCard got bit by a general purpose function in their execution environment after endlessly complaining about the security of using general purpose hardware as a hardware wallet?
Also how are we turning a blind eye so fast on open sats… sometime you have to hold integrity over money.
I hear rumors of big donations to catching up on the audit backlog - great… but there had better be a lot more resignations or governance changes in the next couple weeks before we accept open sats as a neutral actor.
One spurt of money doesn’t fix a decade of biased decision making.
What’s your read on the current state for private repos? Supposedly buzz is the best as a self-hosted community yeah? Is the other tooling mostly public repos only?