Tootfinder

Opt-in global Mastodon full text search. Join the index!

@primonatura@mstdn.social
2026-06-29 14:00:31

"Maine's first 'turtle tunnels' help endangered reptiles cross a 'highway of death'"
#US #USA #America #Maine

@fanf@mendeddrum.org
2026-06-14 08:42:01

from my link log —
Inko: Friendship ended with the garbage collector.
yorickpeterse.com/articles/fri
saved 2021-08-26

@NFL@darktundra.xyz
2026-07-08 14:10:25

Mac Jones recalls 'crazy journey' to 49ers after being passed over during 2021 NFL Draft nfl.com/news/mac-jones-crazy-j

@ubuntourist@mastodon.social
2026-06-16 17:42:24

Sean Penn to direct January 6 drama with Bradley Cooper set to star
#news

@arXiv_csCR_bot@mastoxiv.page
2026-07-24 07:55:47

Security Vulnerability Patterns in AI-Generated Code: A Cross-Model Comparative Study
Shanna M. Kahn, John D. Hastings
arxiv.org/abs/2607.20713 arxiv.org/pdf/2607.20713 arxiv.org/html/2607.20713
arXiv:2607.20713v1 Announce Type: new
Abstract: LLM-based coding tools enable non-expert users to generate routine automation scripts that may enter enterprise workflows without meaningful security review. This study examines that risk directly. Code was collected from ChatGPT, Microsoft Copilot, and Google Gemini using identical prompts across three automation domains. Claude Code performed a standardized vulnerability review. Each identified vulnerability was scored using CVSS v3.1 and mapped to the OWASP Top 10:2021 and the MITRE ATT&CK frameworks. Every script contained exploitable vulnerabilities. Nine of the 17 identified vulnerability classes appeared in code from all three models, while 14 of the 17 vulnerability classes appeared in at least two models. The weighted CVSS scores across platforms differed by less than 10%. The risk is not tied to any particular model but rather to the task category. Organizations should therefore ask not which tool to trust, but instead whether LLM-generated automation code should be deployed without review.
toXiv_bot_toot

@fanf@mendeddrum.org
2026-05-05 14:42:02

from my link log —
Behavior inheritance in Rust.
abadcafe.wordpress.com/2021/01
saved 2021-06-11

@michabbb@social.vivaldi.net
2026-05-13 20:49:09

⚡ What triggered it: GitHub rolled out a new token format for GitHub App installation tokens: ghs__. Base64url encoding uses - chars, which Composer's 2021-era regex didn't permit. Any such token would fail validation and leak.
😱 Making it worse: GitHub Actions' secret masker failed to redact the token. Symfony Console wraps error output with ANSI sequences, bypassing masking. Popular actions like shivammathur/setup-php auto-register GITHUB_TOKEN — no special config needed …

@fanf@mendeddrum.org
2026-07-18 14:42:02

from my link log —
An incomplete list of mistakes in the design of CSS.
wiki.csswg.org/ideas/mistakes
saved 2021-01-24 dotat.at/:/…

@fanf@mendeddrum.org
2026-07-04 08:42:03

from my link log —
Reverse engineering Prodigy.
vintagecomputing.com/index.php
saved 2021-01-16

@buercher@tooting.ch
2026-05-14 15:50:12

Parteien kritisierten 2021 einhellig und scharf den Tages Anzeiger für seine Recherchen zum Spitalskandal. Diese gemeinsame schönredende Erklärung sieht heute ziemlich alt aus, und die Parteien sollten sich entschuldigen. “Wir bleiben dran. “ fdp-bezirkbuelach.ch/aktuell/n

@fanf@mendeddrum.org
2026-07-05 08:42:03

from my link log —
Pink Floyd’s Young Lust telephone signalling explained.
telephoneworld.org/landline-te
saved 2021-10-16