oss-sec mailing list archives

Re: 33 Vulnerabilities in cJSON


From: Peter Gutmann <pgut001 () cs auckland ac nz>
Date: Sat, 1 Aug 2026 02:04:06 +0000

Collin Funk <collin.funk1 () gmail com> writes:

Complaining about free software maintainers, who are presumably not funded by
the projects (some certainly being corporate) depending on it, while also
admitting that you had AI write part of the article for you (as in the author
of the post, not the email I am replying to) because you are too lazy is
certainly a choice.

I assume you're new to this process so I'll explain: When someone submits bug
reports to your project that help fix problems, the polite thing to do is to
say "thanks for the time you've taken to help improve the project", not
"FOAD", which tends to discourage future contributions.

For the record, if anyone wants to send me a bug report for my code I'll
accept it whether you found it yourself, used an AI, or it came to you in a
weird dream you had after a dodgy vindaloo.

Peter (wearing my someone-has-to-say-these-things hat).

Current thread: