Welcome to the strip mining era of open source security
Open source software is in for a rough 2026 summer. If you’re an Open Source maintainer, there’s something afoot you should already know about. If you’re an OSS user, you should be aware of it as it’ll explain some behavior around you that might otherwise seem odd.
TL;DR: High volume, LLM-powered scanning for security vulnerabilities is going to uncover lots of security issues in anything with public source code.
This all started a few months ago
Historically, Metabase averaged 10 submissions p...
Read more at metabase.com