Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dchanm
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
dchanm
11y ago
We're working something similar at Patchwork ( https://patchworksecurity.com/ ) . You tell us what packages are installed and we notify you when a new security update is released. Right now we're focusing on distro
2.
▲
by
dchanm
11y ago
Hi, We understand your concerns with the current install mechanisms. We're working toward providing multiple options similar similar to sandstorm.io https://docs.sandstorm.io/en/latest/install/ There is
3.
▲
by
dchanm
11y ago
Pakiti looks like an interesting tool. Development seems to have slowed down in 2013, but the feature set might have been stable by then. We'll definitely look into this. Thanks deadfece!
4.
▲
by
dchanm
11y ago
Hi yaworsk, We're working on improving our API documentation. You can develop against our API and not use the supplied client. https://patchworksecurity.com/docs/
5.
▲
by
dchanm
11y ago
I believe this issue is fixed now. https://github.com/PatchworkSecurity/cleansweep/issues/8 Could you try running the script again?
6.
▲
by
dchanm
11y ago
"It would be a much better design if it worked the other way around: Aggregate recent security patches into a database and send those to the servers, and have them do a local compare of vulnerabilities. You could charge for the databas
7.
▲
by
dchanm
11y ago
Hi k33n, Thanks for sharing what you learned. We will look into integrating with existing security tools. In the meantime, we believe that providing a security notifications API to users is valuable.
8.
▲
by
dchanm
11y ago
Hi mmaunder, e-mail notifications are our current callback mechanism but that will expand. The goal of our API is to allow you to consume the vulnerability data in a way that is more beneficial to you e.g Slack, CI. You could have a workflo
9.
▲
by
dchanm
11y ago
Hi DoubleMalt, Thanks for the link. I've filed an issue and should have this fixed tonight https://github.com/PatchworkSecurity/cleansweep/issues/7
10.
▲
by
dchanm
11y ago
Hi halite! 1. We've got agents listening to incoming feeds, and did the work to ingest all the historical vulnerability data we could find. 2. We're focusing on apt installed packages for our initial release. 3 & 4. We haven&#
11.
▲
by
dchanm
11y ago
Hi, our roadmap includes hooking into CI where your CI can ask our API Is the current project state vulnerable? yes) Here are a list of dependencies you need to update, run your test again no) Good, proceed with deploy This is a little furt
12.
▲
by
dchanm
11y ago
Hi, can you tell me the version of curl you're running with curl -V Also send me an email at david@patchworksecurity.com and I'll get it working for you.
13.
▲
by
dchanm
11y ago
If you want to be extra cautious you can verify that the script hasn't changed with our release key https://patchworksecurity.com/releases.txt The latest release (2.0.0) has been signed by my key 0x85C64E20
14.
▲
by
dchanm
11y ago
Hi, the shell script is an implementation of our API. You can implement your own client against our API endpoints. This gives you complete control of what package data you send to us. If you only care about OpenSSL, you can create a machine
15.
▲
by
dchanm
11y ago
Hi, we decided to make it easy to setup the tool and run it. The source code is available on GitHub https://github.com/PatchworkSecurity/cleansweep/blob/master/... The comments explain what is happening
16.
▲
by
dchanm
11y ago
Hey, I’m David, the other co-founder of Patchwork Security. I was working on AppSec at Mozilla when Shellshock came out, then the next variant and the next. The OpSec team diligently followed new developments, but there had to be a better w