Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 2 days ago

chicken nuget

Insecure #curl packages hosted by Microsoft. They think it's fine.

https://daniel.haxx.se/blog/2026/03/12/chicken-nuget/

daniel.haxx.se

chicken nuget

Background: nuget.org is a Microsoft owned and run service that allows users to package software and upload it to nuget so that other users can download it. It is targeted for .Net developers but there is really no filter in what you can offer through their service. Three years ago I reported on how nuget … Continue reading chicken nuget →
6
  • Copy link
  • Flag this post
  • Block
older
@older@mstdn.social replied  ·  activity timestamp 7 hours ago

@bagder
I think I have asked you about this already, but please consider nuget prefix reservation for "Curl":
https://learn.microsoft.com/en-us/nuget/nuget-org/id-prefix-reservation

ID Prefix Reservation

Package ID Prefix Reservation feature description and author guide.
1
  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 5 hours ago

@older why would I spend another second trying to help their security?

1
  • Copy link
  • Flag this comment
  • Block
older
@older@mstdn.social replied  ·  activity timestamp 3 hours ago

@bagder
Valid point.
I also now think it would only make sense if there would exist official curl NuGet package.

  • Copy link
  • Flag this comment
  • Block
Tina H
@tina@mastodon.babb.no replied  ·  activity timestamp 8 hours ago

https://www.nrk.no/bokbrevet/bokbrevet-_65-hvor-blir-det-av-de-minneverdige-karakterene-i-samtidslitteraturen_-1.17797235 - kanskje to grunner, her ... det er norsk, og vi tror på "seriøs litteratur"

Tro meg, ingen kommer nevne Tengel på den DER lista ...

NRK

Bokbrevet #65 Hvor blir det av de minneverdige karakterene i samtidslitteraturen?

Jeg husker nesten ingen hoved­personer fra norske romaner de siste årene.
  • Copy link
  • Flag this comment
  • Block
TheTomas
@TheTomas@social.toot9.de replied  ·  activity timestamp 2 days ago

@bagder Yeah, this is exactly the way, how Microsoft (and btw. most of Bigtec) understand live governance.

  • Copy link
  • Flag this comment
  • Block
Safigo
@safigo@c.im replied  ·  activity timestamp 2 days ago

@bagder I have a strong feeling you've already written about #Microsoft using outdated #curl version somewhere.

Am I hallucinating?

1
  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 2 days ago

@safigo sure, I link to my previous nuget complaint in the post: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/ - but I probably did it more times as well

daniel.haxx.se

The curl nuget story

Recently there has been an interesting debate in the Open Source world where people have objected to being called "Suppliers" as in Supply Chain Security when you are but an Open Source developer offering your code to the world for free and at no cost but also without any warranties. That is not a supplier, … Continue reading The curl nuget story →
  • Copy link
  • Flag this comment
  • Block
Peter Jeschke
@peter@jeschke.dev replied  ·  activity timestamp 2 days ago

@bagder I think this isn't a nuget problem, but just package managers in general? For example, the central maven repository has loads of libraries that ship some ancient curl versions: https://central.sonatype.com/search?q=curl

I would assume the same for every other ecosystem as well

Maven Central

Maven Central: Search

Search and discover Java packages with our advanced search functionality.
  • Copy link
  • Flag this comment
  • Block
Luís Correia
@luisfcorreia@mastodon.social replied  ·  activity timestamp 2 days ago

@bagder I might be thinking the wrong thing but can curl project upload curl packages to the chickencoop so that 'at least' some packages are from known source?

I know that's not your problem to fix, but still...

1
  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 2 days ago

@luisfcorreia sure, in theory that could possibly be done. But to me that would feel like giving in to them and accepting this as how it needs to be so I will not participate in that.

  • Copy link
  • Flag this comment
  • Block
Log in

Gnar 🔥 social

This is a Bonfire Federated social instance for those that enjoy gnarly adventures. Whether it's shredding mountains or slaying guitars, from action sports to art.

Gnar 🔥 social: About · Code of conduct · Privacy · Users · Instances
Gnar;🔥 social · 1.0.0-rc.3.6 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login