3 ms·
Nonsensical corporate posturing. "Microsoft will contribute expertise, resources, and AI technologies to help responsibly identify and fix vulnerabilities" As
by romaniv 3mo ago
Nonsensical corporate posturing.
"Microsoft will contribute expertise, resources, and AI technologies to help responsibly identify and fix vulnerabilities"
As a reminder, Microsoft runs NPM and GitHub. Microsoft has access to the best AI models and massive data centers. Despite that, their own products are rapidly getting worse at security and their services are central hubs through which various exploits are propagated. They are not making things better, they are actively and rapidly making things worse.
--
For a great example of how Microsoft deals with security issues within their own Open-Source projects, I recommend reading this GitHub thread:
https://github.com/dotnet/efcore/issues/38257 https://github.com/dotnet/efcore/issues/38257
EF core currently distributes a version of SQLite that has a severe vulnerability. The issue was discovered over a year ago. It was fixed by SQLite within one week. EF core didn't mark their driver as vulnerable until a user recently reported it, got bounced around and argued with developers. The current stable version of .NET core will only get a fix in roughly two months.
- playorizaya 3mo ago[flagged]
- josteink 3mo ago> So, MS builds VSCode - doesn't even fork Atom to do so. Looks identical to it. They built it from scratch. Bigger. Slower. Someone needs to fix a memory leak here. Atom was famously slow. Even among people using it and championing it. VSCode totally wowed people not just because it was faster, but because it was essentially the first «real» Electron-app which proved Electron-apps could have near native performance. You got this part 100% backwards.
- jgalar 3mo ago> proved Electron-apps could have near native performance I don't think that's true at all. Try running Zed or Sublime.
- playorizaya 3mo ago> Atom was famously slow It's your linter And Electron apps do not have near native performance lmao Not even close. And neither does VS Code haha. Definitely slow just like Atom. You missed the point
- WorldMaker 3mo agoAlso, big chunks of VSCode predated Atom. (The Monaco code editor was embedded inside IE10/11/Spartan Edge and parts of the Azure Portal and Azure Dev Ops.) Electron was the excuse to make it its own deliverable and not just only embedded inside other web projects. (Which is also why VSCode was not even a fork of Atom and easily beat Atom's performance at launch because it was already a battle hardened editor.)
- jkrejcha 3mo ago> a version of SQLite that has a severe vulnerability Calling CVE-2025-70873 a severe vulnerability is a bit overplaying it imo. The vulnerability requires that you allow an attacker to import an arbitrary ZIP file I looked at the vulnerability in question by the way, CVE-2025-70873, and it really is not that severe unless you're allowing users to import arbitrary ZIP files
- romaniv 3mo agoThat's not the only CVE in question. The issue also involves CVE-2025-6965.