Sign in

Frédéric Bonnet 🇺🇦 @codinbzh

@codinbzh.bsky.social
166 followers 306 following 160 posts

Software engineer @ Alan (opinions mine) | ex Shopify | Toolmaker | #SoftwareCrafter | ❤️ C | ❤️ Tests | ❤️ Doc generators | @codinbzh@mastodon.comwork.io

PostsRepliesMedia
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Barry O'Sullivan @barryosull.bsky.social · 01/10/2026
Refactoring is harder than adding behaviour due to entropy. Refactoring is fighting entropy, while writing code adds it.
154
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Mathis Hammel-Brylinski @mathishammel.bsky.social · 30/09/2026
Lundi j'ai enfin réussi à choper une clé API pour Jev, et j'ai eu envie de vérifier à quel point c'était une enième hype de la communauté IA. J'ai fait un benchmark pour comparer ce modèle à des LLM classiques sur de la classif de texte, les résultats sont DINGUES 🤯 agoratlas.com/blog/evaluat...
Résultats de mon benchmark Jev vs LLM : les 15 configurations de Jev battent le meilleur des 20 LLMs. La configuration en tête du benchmark est 21x moins chère, 15x plus rapide et 35% meilleure que GPT-6 Sol.
4336
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 22/09/2026
Allez hop on bloque les cons.
001
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 22/09/2026
Ah oui je me souviens comment on a arrêté la guerre contre les nazis en 1945, heureusement qu'on avait la diplomatie hein.
130
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Grompf @grompf3.eurosky.social · 21/09/2026
"À cette gauche qui répète depuis bientôt 5 ans les mêmes formules sur l’Ukraine: je vous réponds parce que vous êtes ma douleur et ma plus grande déception...."
À cette gauche qui répète depuis bientôt 5 ans les mêmes formules sur l’Ukraine: je vous réponds parce que vous êtes ma douleur et ma plus grande déception. À l’extrême droite dont les liens financiers avec la Russie sont documentés, je n’ai pas de questions.

Mais vous, allez au bout de vos phrases.

« Nous voulons arrêter la guerre. »

Nous aussi. Vous pensez vraiment que quelqu’un veut la paix davantage que ceux qui se réveillent avec des drones audessus de leur lit, qui enterrent leurs enfants, qui vivent amputés, sans maison, ou sous occupation russe ?

La question n’est pas de savoir qui veut la paix. La question est de savoir comment on arrête celui qui fait la guerre. Et là, soudain, vos phrase
722394
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
DaB @oursobouros.bsky.social · 17/09/2026
[Appel à coup de pouce] Après beaucoup de non-réponses, je tente le coup ici. On cherche un stage d'observation de 5 jours fin novembre pour l'ado de 14 ans vers Lyon, Grenoble, Valence, dans : -conception jeu vidéo -conception logicielle -aéronautique Si vous bossez dans un de ces domaines...🙏
732132
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Bearstech @bearstech.com · 18/09/2026
Mozilla et Mistral annoncent l'intégration de modèles Mistral dans Firefox. "Mistral and Mozilla are bringing open, private and multilingual AI to your web browser" 👉 mistral.ai/news/mist...
Illustration de l'article
032
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
zeldman @zeldman.bsky.social · 18/09/2026
“Let me make it clear: without people at the top of their game sharing their experience and knowledge—regardless of whatever ‘game changing’ technology is in place—we are pulling up the ladders and committing our industry to stagnation and death.” bell.bz/youll-miss-p...
bell.bz
You’ll miss publishers when they’re gone
Ever since Piccalilli started to get traction, I’ve always seen CSS-Tricks, Smashing Magazine and A List Apart (among others) as peers. We all help each other behind the scenes and importantly, back…
111439
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 16/09/2026
Premier meetup Software Crafters Rennes de la rentrée chez Oxxeo !
Salle avec des chaises et des gens dessus, avec un projecteur et deux speakers
020
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 16/09/2026
A tool that you're constantly fighting with is not a good tool, regardless of its sophistication or the services it provides. At some point you will get hurt. AI is no exception here. #AIFatigue
000
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 15/09/2026
Ce qui m'inquiète c'est l'impact d'un nombre considérable de désorbitations sur l'atmosphère et donc le climat, j'avais vu passer un article pas réjouissant sur Starlink il y a quelques années.
010
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Danny Moerkerke @dannymoerkerke.bsky.social · 15/09/2026
The killer feature of PWAs is not that they update automatically or they’re cross-platform. The absolute killer feature of PWAs is that they can be freely distributed without any app store dependency No risk that one party can kill your distribution and end your business. That’s a killer feature.
1344
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Chris Palmer @fugueish.bsky.social · 14/09/2026
Indeed, native apps should be avoided whenever possible: nooneshappy.com/article/nati...
nooneshappy.com
Native Apps Should Be Avoided Whenever Possible — No One's Happy
Why native apps have become privacy liabilities, and why the browser is almost always the better choice.
0136
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Le Pavé numérique @lepavenumerique.com · 11/09/2026
Cette semaine dans le Pavé numérique premium : après avoir encouragé la multiplication des écrans à l'école, de plus en plus de pays prônent le retour au papier, par Lila Meghraoua lepavenumerique.subs...
Extrait du Pavé numérique :

« Ce coup d’arrêt new-yorkais rejoint le grand reflux mondial du numérique à l’école. Tandis que la France organise sa pause numérique — téléphone remisé dans des casiers le matin — dans 200 collèges volontaires, le Royaume-Uni et les Pays-Bas bannissent l’appareil des écoles. Le plus marquant reste la Suède, pionnière zélée de l’apprentissage sur tablettes. En cause : des tests qui accusent un recul des compétences en lecture des jeunes Suédois. Résultat ? Rétropédalage en quatrième vitesse sur fond de dizaines de millions d’euros pour s’équiper à nouveau de manuels scolaires. »
042
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
🦔 ErinaceusFrance @erinaceus.fr · 11/09/2026
Trois liens pour vous apporter un peu d'optimisme [1] 2050Now www.youtube.com/watch?v=Ds8g...
youtube.com
Je visite le seul centre de soins pour hérissons de Paris
YouTube video by 2050NOW
145
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 09/09/2026
So yes, generative AIs are currently producing a number of artworks, and, like a malevolent genie granting us wishes, they are also making us realize that we didn't care about these artworks all along. Because the artworks were made for humans to produce.
static.klipy.com
Bob Ross: Painting Wisdom
Alt: Bob Ross: Painting Wisdom The secret to doing anything is believing that you can do it. Anything that you believe you can do strong enough, you can do. Anything. As long as you believe.
010
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Gro-Tsen @gro-tsen.bsky.social · 20/07/2026
So yes, LLMs are currently solving a number of famous conjectures, and, like a malevolent genie granting us wishes, they are also making us realize that we didn't care about these conjectures all along. Because the conjectures were made for human brains to work on. •24/38
1388
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Daniel Lemire @lemire.bsky.social · 03/09/2026
Python sets and dictionaries can have quadratic-time performance lemire.me/blog/2026/09/03/python-se…
012
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Human Coders News @news.humancoders.com · 03/09/2026
Prela : un langage de requête alternatif à SQL basé sur les relations binaires
prela-lang.org
Prela Tutorial
0115
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
gdr-macs.bsky.social @gdr-macs.bsky.social · 02/09/2026
#Stage : [Jobs] Offres de stage au sein de l'équipe RAINBOW à l'IRISA, à Rennes rattachement : IRISA UMR 6074 site web : team.inria.fr/rainbow/cate... lien direct : gdr-macs.fr/node/5414
team.inria.fr
Internships – Rainbow
001
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Eiji Kitamura / えーじ @agektmr.com · 28/08/2026
By setting up `https://<your-domain>/.well-known/change-password` to redirect (302/303/307) to your actual password update page, Chrome, Safari, and major password managers can guide users directly to your change password form.
15611
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Shirley 🧡🧡🧡 @tatashishi.bsky.social · 23/08/2026
Je ne pensais pas en arriver là mais voilà je franchis ce pas pour aider ma maman. Avec mes frères et sœurs, nous avons sorti notre maman d'une situation d'emprise violente et destructrice.
2811
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Ivan Gaudé @ivanlefou.eurosky.social · 17/08/2026
"La crypto, c'est la liberté, une réponse aux banques qui savent tout de nous"
47437
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 16/08/2026
At this stage, the only way to keep my sanity is to stop giving a fuck.
000
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 16/08/2026
The real pain of being neurodivergent during a global crisis is believing we’ll make it because people can’t be that stupid and irrational, until you realize they are.
100
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Danny Moerkerke @dannymoerkerke.bsky.social · 11/08/2026
If you still think native apps are more secure than web apps: nooneshappy.com/article/nati...
nooneshappy.com
Native Apps Should Be Avoided Whenever Possible — No One's Happy
Why native apps have become privacy liabilities, and why the browser is almost always the better choice.
042
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Labolycée @labolycee.org · 27/07/2026
L’outil ultime pour préparer l’éclipse de Soleil du 12 août eclipsemap.xyz Il a même été prévu l’obstruction de la vue par les reliefs environnants.
Carte d’Espagne issue du site https://eclipsemap.xyz/
515986
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
noyb – European Center for Digital Rights @noyb.eu · 26/07/2026
👋⚖️ Therefore, the tracking industry needs you to waive your rights. That’s why they invented cookie banners, which often are deliberately misleading as well as annoying
192
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
noyb – European Center for Digital Rights @noyb.eu · 26/07/2026
🍪🚫 It's time to kill the cookie banner – and end the endless tracking circus! ⏮️ You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default.
A woman sitting at her computer looking at at an endless amount of cookie banner pop ups coming out of her screen.
24526
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Michaël Szadkowski ☑️ @szadkowski.fr · 24/07/2026
Un lecteur @lemonde.fr signalait en commentaire que mettre "-ai" à la fin d'une recherche Google désactivait les résumés AI. Testé ce matin, ça fonctionne. Merci, cher lecteur !
22493320
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Camille Roux @camilleroux.com · 24/07/2026
L'impact écologique de l'IA, chiffres en main : consommation électrique à l'entraînement, à l'inférence, eau, ressources minières. Hugo Lassiège reste factuel pour donner de quoi construire un avis solide. ⬇️ eventuallycoding.com/p/ia-et-ecolog…
Visuel de couverture d'article sur fond bleu nuit, avec le titre en blanc : « IA et écologie, fantasme ou bouc émissaire pratique ? », accompagné d'un sous-titre introduisant le sujet comme l'un des plus polarisés de la tech.
151
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 19/07/2026
Ça va bien plus loin que ça puisque ça a servi à pérenniser la ségrégation raciale, cherche "redlining" pour plus d'infos.
020
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Costa Samaras @costasamaras.com · 19/07/2026
Could Excel be conscious? We surveyed more than Jan 1 1900 people to find out.
114137692877
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
kevin-palser.bsky.social @kevin-palser.bsky.social · 17/07/2026
I read this moving article recently where a daughter is disassembling her deceased father’s #Zx81 game and appreciating his genius: nachbaur.com/2026/03/11/d...
nachbaur.com
👾 The Dungeon of Ymir: A Daughter, Disassembler, and Her Dad's RPG
My father, Fred Nachbaur, died of cancer in September of 2004. He was 53 years old. I had just moved to Canada not long before, and our relationship, which had always been complicated, never got the r...
2166
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 16/07/2026
The GDPR is one of the most misunderstood regulations ever. No, cookie banners are not mandatory, they never were.
020
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
McGarr Solicitors @mcgarrsolicitors.bsky.social · 14/07/2026
Essential Cookies Aren't Optional, So Stop Asking Permission for Them: One of the most common misconceptions about cookie consent is that websites need permission for every cookie they use. In fact, the opposite is true. mcgarrsolicitors.ie/2026/07/14/esse…
21714
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 15/07/2026
C'est vrai qu'on reçoit pas assez de radiations solaires en ce moment. Ça plus les starlinks de l'autre nazi qui perturbent les observations et flinguent l'atmosphère lors de la désorbitation, ça commence à faire beaucoup. Quelqu'un est partant pour un projet "syndrome de Kessler" en crowdfunding ?
000
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 15/07/2026
Le C++, j'en ai bouffé pendant une bonne 15aine d'années, j'ai suivi de loin les nouvelles versions avec un mélange d'horreur et de circonspection, c'est vraiment le pire langage jamais créé.
010
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Reuters @reuters.com · 14/07/2026
Elon Musk's xAI has installed more than double the number of gas turbines than it has publicly acknowledged to power its Colossus 2 data center project, without federal permits, and the pollution is hitting predominantly Black neighborhoods the hardest reut.rs/4bIghEm
15236041946
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Olivier Poncet 🦝 @ponceto91.bsky.social · 14/07/2026
« Everyone you meet is fighting a battle you know nothing about. Be kind. Always. » Je viens de voir passer cette quote. Sur le fond il avait raison. En pratique la société actuelle n'aide pas.
1274
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 14/07/2026
When you talk to an agent you're talking to yourself. How does that fit with your point of view?
000
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 09/07/2026
Plus d'infos ici pour un débat serein : bsky.app/profile/sola...
000
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 09/07/2026
Tiens justement la mienne est orientée sud-est/nord-ouest, du coup j'ai mis sud/nord car ça doit pas changer grand chose.
000
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 09/07/2026
Big up pour l'appli web, ça permet à tout le monde de l'utiliser sans être verrouillé sur un écosystème propriétaire. Est-ce que c'est une PWA installable ? Dans le cas contraire ça devrait être possible sans trop d'effort via Claude.
000
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
Solal Gendrin @solalgendrin.bsky.social · 08/07/2026
👉👉LES LIENS : Pour les utilisateurs IOS : apps.apple.com/fr/app/nadir... Pour les utilisateurs web / Android : solal3105.github.io/NADIR2/app.h...
apps.apple.com
App NADIR - App Store
Téléchargez l’app NADIR développée par solal gendrin dans l’App Store. Consultez les captures d’écran, les notes et avis, les astuces d’autres utilisateurs, et…
86228
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 09/07/2026
Si optimiser le rafraîchissement de son logement permet ne serait-ce qu'à UN SEUL foyer d'éviter l'achat d'une clim mobile ou même de faire tourner celle qu'il a déjà alors ça compense largement le coût de développement de l'appli. Le débat sur l'IA doit s'inscrire dans une perspective globale.
000
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 02/07/2026
Incredibly proud to be part of Alan's journey so far! (Yes this is Time Square and the NYSE)
NYC Time Square: Nasdaq Congratulates Alan on its $550M Fundraise Valuing The Company At $6.3B

With this new funding, Alan enters a new phase of growth to transform healthcare through prevention, technology and AINYSE Cubes:

Congratulations to Alan's on its $550M Series G at a $6.3B valuation led by Prosus, Teachers, Index, and Dara.

Turning healthcare proactive as it can't wait!NYSE Cubes:

Congratulations to Alan's on its $550M Series G at a $6.3B valuation led by Prosus, Teachers, Index, and Dara.

Turning healthcare proactive as it can't wait!NYSE Cubes:

Congratulations to Alan's on its $550M Series G at a $6.3B valuation led by Prosus, Teachers, Index, and Dara.

Turning healthcare proactive as it can't wait!
030
Frédéric Bonnet 🇺🇦 @codinbzh @codinbzh.bsky.social · 15/05/2026
The end game of AI code assistants is us giving up coding completely and them getting the monopoly on code production, assuming that code is so cheap that it's simpler/faster to rebuild everything from scratch than to maintain and evolve existing code bases. It's a mistake of course.
100
Reposted by Frédéric Bonnet 🇺🇦 @codinbzh
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 11/05/2026
#Mythos finds a #curl vulnerability yes, as in singular one. daniel.haxx.se/blog/2026/05/11/myth…
daniel.haxx.se
Mythos finds a curl vulnerability
yes, as in singular _one_. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model _Mythos_ is _dangerously good_ at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead trickle it out to a selected few companies for a while to allow a few good ones(?) to get a head start and fix the most pressing problems first, before the general populace would get their hands on it. The whole world seemed to lose its marbles. Is this the end of the world as we know it? An amazingly successful marketing stunt for sure. ## My (non-) access Part of the deal with _project Glasswing _was that Anthropic also offered access to their latest AI model to “Open Source projects” via Linux Foundation. Linux Foundation let their project Alpha Omega handle this part, and I was contacted by their representatives. As lead developer of curl I was offered access to the magic model and I graciously accepted the offer. Sure, I’d like to see what it can find in curl. I signed the contract for getting access, but then nothing happened. Weeks went past and I was told there was a hiccup somewhere and access was delayed. Eventually, I was instead offered that someone else, who has access to the model, could run a scan and analysis on curl for me using Mythos and send me a report. To me, the distinction isn’t that important. It’s not that I would have a lot of time to explore lots of different prompts and doing deep dive adventures anyway. Getting the tool to generate a first proper scan and analysis would be great, whoever did it. I happily accepted this offer. (I am purposely leaving out the identity of the individual(s) involved in getting the curl analysis done as it is not the point of this blog post.) ## AI scans of curl Before this first Mythos report, we had already scanned curl with several different very capable AI powered tools (I mean _in addition to_ running a number of “normal” static code analyzers all the time, using the pickiest compiler options and doing fuzzing on it for years etc). Primarily AISLE, Zeropath and OpenAI’s Codex Security have been used to scrutinize the code with AI. These tools and the analyses they have done have triggered somewhere between _two and three hundred_ bugfixes merged in curl through-out the recent 8-10 months or so. A bunch of the findings these AI tools reported were confirmed vulnerabilities and have been published as CVEs. Probably a dozen or more. Nowadays we also use tools like GitHub’s Copilot and Augment code to review pull requests, and their remarks and complaints help us to land better code and avoid merging new bugs. I mean, we still merge bugs of course but the PR review bots regularly highlight issues that we fix: our merges would be worse without them. The AI reviews are used _in addition_ to the human reviews. They help us, they don’t replace us. We also see a high volume of high quality security reports flooding in: security researchers now use AI extensively and effectively. Security is a _top_ _priority_ for us in the curl project. We follow every guideline and we do software engineering properly, to reduce the number of flaws in code. Scanning for flaws is just one of many steps to keep this ship safe. You need to search long and hard to find another software project that makes as much or goes further than curl, for software security. Steps involved in keeping curl secure ## May 6, 2026 It was with great anticipation we received the first source code analysis report generated with Mythos. Another chance for us to find areas to improve and bugs to fix. To make an even better curl. This initial scan was made on curl’s git repository and its master branch of a certain recent commit. It counted 178K lines of code analyzed in the src/ and lib/ subdirectories. The analysis details several different approaches and methods it has performed the search, and how it has focused on trying to find which flaws. A fun note in the top of the report says: > curl is one of the most fuzzed and audited C codebases in existence (OSS-Fuzz, Coverity, CodeQL, multiple paid audits). Finding anything in the hot paths (HTTP/1, TLS, URL parsing core) is unlikely. … and it correctly found no problems in those areas. Completely unscientific poll on Mastodon about people’s expectations for Mythos scanning curl ## The size of curl curl is currently 176,000 lines of C code when we exclude blank lines. The source code consists of 660,000 words, which is 12% more words than the entire English edition of the novel War and Piece. On average, every single production source code line of curl has been written (and then rewritten) 4.14 times. We have polished on this. Right now, the existing production code in git master that still remains, has been authored by 573 separate individuals. Over time, a total of 1,465 individuals have so far had their proposed changes merged into curl’s git repository. We have published 188 CVEs for curl up until now. curl is installed in over _twenty million instances_. It runs on over _110 operating systems_ and _28 CPU architectures_. It runs in every smart phone, tablet, car, TV, game console and server on earth. ## Five findings became one The report concluded it found **five** “Confirmed security vulnerabilities”. I think using the term _confirmed_ is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take. Five issues felt like nothing as we had expected an extensive list. Once my curl security team fellows and I had poked on the this short list for a number of hours and dug into the details, we had trimmed the list down and were left with _one_ confirmed vulnerability. The other four were three false positives (they highlighted shortcomings that are documented in API documentation) and the fourth we deemed “just a bug”. The single confirmed vulnerability is going to end up a _severity low_ CVE planned to get published in sync with our pending next curl release 8.21.0 in late June. The flaw is not going to make anyone grasp for breath. All details of that vulnerability will of course not get public before then, so you need to hold out for details on that. The Mythos report on curl also contained a number of spotted bugs that it concluded were not vulnerabilities, much like any new code analyzer does when you run it on hundreds of thousands of lines of code. All the bugs in the report are being investigated and one bye one we are fixing those that we agree with. All in all about twenty bugs that are described and explained very nicely. Barely any false positives, so I presume they have had a rather high threshold for certainty. curl is certainly getting better thanks to this report, but counted by the volume of issues found, all the previous AI tools we have used have resulted in larger bugfix amounts. This is only natural of course since the first tools we ran had many more and easier bugs to find. As we have fixed issues along the way, finding new ones are slowly becoming harder. Additionally, a bug can be small or big so it’s not always fair to just compare numbers ## Not particularly “dangerous” My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing. This is just _one_ source code repository and maybe it is much better on other things. I can only tell and comment on what it found here. ## Still very good But allow me to highlight and reiterate what I have said before: AI powered code analyzers are _significantly_ better at finding security flaws and mistakes in source code than any traditional code analyzers did in the past. All modern AI models are good at this now. Anyone with time and some experimental spirits can find security problems now. The high quality chaos is real. Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools. Mythos will, and so will many of the others. Not using AI code analyzers in your project means that you leave adversaries and attackers time and opportunity to find and exploit the flaws you don’t find. ## How AI analyzers differ * They can spot when the comment says something about the code and then conclude that the code does not work as the comment says. * It can check code for platforms and configurations we otherwise cannot run analyzers for * It “knows” details about 3rd party libraries and their APIs so it can detect abuse or bad assumptions. * It “knows” details about protocols curl implements and can question details in the code that seem to violate or contract protocol specifications * They are typically good at summarizing and explaining the flaw, something which can be rather tedious and difficult with old style analyzers. * They can often generate and offer a patch for its found issue (even if the patch usually is not a 100% fix). ## More details from the report **Zero memory-safety vulnerabilities found.** Methodology note: this review is hand-driven analysis using LLM subagents for parallel file reads, with every candidate finding re-verified by direct source inspection in the main session before being recorded. The CVE to variant-hunt mapping was built from curl’s own vuln.json. No automated SAST tooling was used. This outcome is consistent with curl’s status as one of the most heavily fuzzed and audited C codebases. The defensive infrastructure (capped dynbufs everywhere, `curlx_str_number` with explicit max on every numeric parse, `curlx_memdup0` overflow guard, CURL_PRINTF format-string enforcement, per-protocol response-size caps, pingpong 64KB line cap) systematically closes the bug classes that would normally be productive in a codebase this size. Coverage now includes: all minor protocols, all file parsers, all TLS backends’ verify paths, http/1/2/3, ftp full depth, mprintf, x509asn1, doh, all auth mechanisms, content encoding, connection reuse, session cache, CLI tool, platform-specific code, and CI/build supply chain. ## AI finds existing kinds of errors It should be noted that the AI tools find the usual and established kind of errors we already know about. It just finds new instances of them. We have not seen any AI so far report a vulnerability that would somehow be of a novel kind or something totally new. They do not reinvent the field in that way, but they do dig up more issues than any other tools did before. ## More to find These were absolutely not the last bugs to find or report. Just while I was writing the drafts for this blog post we have received more reports from security researchers about suspected problems. The AI tools will improve further and the researchers can find new and different ways to prompt the existing AIs to make them find more. We have not reached the end of this yet. I hope we can keep getting more curl scans done with Mythos and other AIs, over and over until they truly stop finding new problems. ## Credits Thanks to Anthropic and Alpha Omega for providing the model, the tools and doing the scan for us. Thanks also to the individual who did the scan for us. Much appreciated! Top image by Jin Kim from Pixabay Thanks for flying curl. It’s never dull.
7247121