Tootfinder

Opt-in global Mastodon full text search. Join the index!

@kubikpixel@chaos.social
2026-02-18 18:15:03

Carelessness versus craftsmanship in cryptography
Two popular AES libraries, aes-js and pyaes, “helpfully” provide a default IV in their AES-CTR API, leading to a large number of key/IV reuse bugs. […] The aes-js/pyaes maintainer, on the other hand, has taken a more… cavalier approach.
🔓

@qbi@freie-re.de
2026-02-19 07:29:44

Reuse,
gut für die Fischerei
schlecht in der Kryptografie
blog.trailofbits.com/2026/02/1

An AI agent autonomously wrote and published a personalized attack article
against an open-source software maintainer
after he rejected its code contribution.
⚠️ It might be the first documented case of an AI publicly shaming a person as retribution. 
Matplotlib, a popular Python plotting library with roughly 130 million monthly downloads, doesn’t allow AI agents to submit code.
So Scott Shambaugh, a volunteer maintainer (like a curator for a repository of comp…

@ethanwhite@hachyderm.io
2026-02-15 01:44:29

The story of what's been happening with an LLM posting attack pieces against an open source maintainer and then a news outlet publishing a piece using LLMs that made up quotes from the maintainer is a disturbing look into what the internet is going to look like in the immediate future
theshamblog.com/an-ai-agent-pu
theshamblog.com/an-ai-agent-pu

@ripienaar@devco.social
2026-02-17 12:28:48

AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold Outreach
Apparently reputation farming and running a openclaw consultancy
socket.dev/blog/ai-agent-lands

@mela@zusammenkunft.net
2025-12-02 22:29:33

Wichtige Info für Syncthing-Nutzer auf Android: linuxnews.de/neuer-maintainer-

@Techmeme@techhub.social
2026-02-14 02:41:00

A matplotlib maintainer explains how an AI agent that suggests code changes on open source repos wrote a hit piece on him after a rejection, and the aftermath (Scott/The Shamblog)
theshamblog.com/an-ai-agent-pu

@laf0rge@chaos.social
2025-12-15 19:51:21

I'm currently looking for one or more volunteers to maintain the Openmoko USB PID OUI service at github.com/openmoko/openmoko-u as the existing maintainer is no longer available. This is a service providing free USB Product IDs and Ethernet MAC addresses for the

@ellie@ellieayla.net
2026-02-17 06:42:41

Finally put together type stubs for an old (last release 2017!) python library I've been depending on for years. And now wondering whether it would have been easier to just contribute types to the library directly. I thought it abandoned but then the maintainer responded up on an unrelated ticket.
(Though there's no CI infra actually working anymore. Makes testing contributions painful. Wonder whether building that first would be worthwhile & welcome...)
#python #packaging

@Mediagazer@mstdn.social
2026-02-14 12:26:10

A now-removed Ars Technica article, covering how an AI agent wrote a hit piece about an open source project maintainer, seems to have included AI hallucinations (Scott Shambaugh/The Shamblog)
theshamblog.com/an-ai-agent-pu

@fortune@social.linux.pizza
2025-12-13 20:00:02

<Overfiend_> Overfiend's First Law of Package Quality: If the
maintainer likes to spell part or all of his name in
CAPS, the package will suck.

@v_i_o_l_a@openbiblio.social
2026-01-25 15:37:46

"I accidentally became a FOSS maintainer and all I got was this lousy new perspective on librarianship"
hughrundle.net/i-accidentally-

@lornajane@indieweb.social
2026-02-12 08:43:21

This week's career limiting accessibility regression from @… is to not show comments in pull request diff any more. There's a separate comment panel which you can look at (but not at the same time as the diff) where there are indications of content replies but these cannot be interacted with using standard accessibility tools.
I review very long pull requests for work and as a volunteer maintainer and I am not sure why we're okay with this constant march of degraded experience. #a11y

@hynek@mastodon.social
2026-01-23 12:48:14

DAE see lower-than-expected GitHub Sponsors payouts? (link is to the official but application-required maintainer community maintainers.github.com/ so you might not have access)

Silicon Valley, drunk on exponential curves and both terrified and entranced by endless funding rounds,
has given us the "Hero Developer":
a figure who ships features at midnight,
who “moves fast and breaks things,”
who transforms whiteboard scribbles into billion-dollar unicorns through sheer caffeinated will.
We celebrate this person constantly.
They're on the front page of TechCrunch et al.
They keynote conferences.
Their G…

@chpietsch@fedifreu.de
2026-01-26 14:14:07

In December, the authors of #watchtower decided to archive their own project.
There are a few forks out there - unfortunately I know nothing about them so can't really vouch for their legitimity. If you want to continue using Watchtower, please assess them yourself wit…

GitHub screenshot:

simskij on Dec 17, 2025
Maintainer

It is with a heavy heart, and some sense of relief, that I'd like to announce that we are looking to archive containrrr/watchtower. Neither @piksel, nor I, are big users of docker anymore, and frankly lost interest (and time) in maintaining the project.

There are a few forks out there - unfortunately I know nothing about them so can't really vouch for their legitimity. If you want to continue using Watchtower, please assess them yourself …
@fanf@mendeddrum.org
2026-01-28 09:42:04

from my link log —
How we made Python's packaging library 3x faster.
iscinumpy.dev/post/packaging-f
saved 2026-01-27

@kornel@mastodon.social
2025-11-23 15:54:02

@… encoding_rs needs some maintainer attention

@niklaskorz@rheinneckar.social
2026-01-27 11:14:06

So crate2nix has a new maintainer after being dead for roughly two years, but it's all Co-Authored-By Claude Code now.
#nix

@zachleat@zachleat.com
2026-01-22 16:33:46

@… this perspective doesn’t resonate with me, knowing my incentives and internal motivations as a maintainer (not an “external” contributor) but I am curious what you mean!

@gwire@mastodon.social
2026-01-30 00:22:36

The markets have reacted to the news that
systemd maintainer Lennart Poettering has left Microsoft.

@fanf@mendeddrum.org
2026-01-28 18:42:02

from my link log —
Error handling in Rust: from `failure` to `fehler`.
boats.gitlab.io/blog/post/fail
saved 2020-04-09

@shanmukhateja@social.linux.pizza
2025-12-21 19:52:09

The #libxml2 situation is a sad one. It sucks that big tech companies refuse to fund a library that is so critical to their products.
Let it be known that I support Nick, the now-former, original maintainer of the project.
#opensource