Hacker Newsnew | past | comments | ask | show | jobs | submit | classicposter's commentslogin

He must be suffering from AI psychosis.


https://github.com/oven-sh/bun/issues/30921

> A CVE wasn’t announced for an HTTP Request Smuggling vulnerability

Even before the acquisition of Anthropic, there had never been a single vulnerability report.

https://github.com/oven-sh/bun/security

Do not use this in production.




https://github.com/oven-sh/bun/security

Surprisingly, they appear to have not disclosed any vulnerabilities whatsoever. It's likely there have been numerous vulnerabilities in the past, but they are all being ignored.

https://x.com/DavidSherret/status/2031432509301428644


This is really poor form given that Anthropic is going around getting all kinds of public goodwill for finding CVEs in other people’s products.


Yeah! Why would the company that stands to make themselves look better in front of an IPO do such a thing?! Next thing you're going to tell me was that this whole rewrite was another marketing ploy to help potentially turn themselves in multi-millionaires!


Yes, it is helpful for a company to be very clear that in a choice between the safety and integrity of their customers, and profit, they are choosing profit.


It's interesting that the developer who spearheaded the hype of Zig abandoned the engineering without addressing the segfault. They could have also taken the approach of gradually porting from Zig to Rust via FFI. Yes, this is a slop show by the AI lab.


Porting TypeScript to Go and coreutils to Rust is understandable given their legitimate background. However, this is just a slop. The original code and tests are of poor quality, so the only thing that can be fixed is segmentation faults...


A former engineer at Bun said that "there was too much vibe coding, but my opinion wasn't taken into consideration."

https://paperclover.net/q+a/2506010139

> - too much ai chatter. so many examples of it failing to work. ill prove it by showing the most recent ai-generated pull request. yep, it’s failing. i will admit that my feedback on the above items were not very loud, but there has been no attempts to correct this vision.


https://x.com/bunjavascript/status/1966806250827714736

Haha, is it really okay not to retract that that the official account previously posted a caricature criticizing Rust?


Yes, it's quite ok to not "retract" a goofy image from months ago. It's harmless fun.


https://github.com/oven-sh/bun/issues/30197

It seems there was an issue where the image API ignored the ICC Profile.(now fixed) Any developer with experience implementing image formats would almost certainly avoid this mistake. This is a problem that cannot be solved with vibe coding. In this situation, the user is merely a guinea pig for bug fixes.


... and that bug was spotted in the canary release, reported and fixed.

Sounds like responsible open source software development to me. That's what pre-releases are for.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: