From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org [79.124.17.100]) by master.gitmailbox.com (Postfix) with ESMTP id 9F12A477D4 for ; Fri, 22 Sep 2023 14:49:42 +0000 (UTC) Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 2F9B568C975; Fri, 22 Sep 2023 17:49:39 +0300 (EEST) Received: from relay2-d.mail.gandi.net (relay2-d.mail.gandi.net [217.70.183.194]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 12C3D68AD99 for ; Fri, 22 Sep 2023 17:49:32 +0300 (EEST) Received: by mail.gandi.net (Postfix) with ESMTPSA id 6176F40008 for ; Fri, 22 Sep 2023 14:49:31 +0000 (UTC) Date: Fri, 22 Sep 2023 16:49:30 +0200 From: Michael Niedermayer To: FFmpeg development discussions and patches Message-ID: <20230922144930.GW8640@pb2> References: <20230707150654.GX1093384@pb2> <168889764928.542.505537875908829599@lain.khirnov.net> <20230922092754.GV8640@pb2> MIME-Version: 1.0 In-Reply-To: X-GND-Sasl: michael@niedermayer.cc Subject: Re: [FFmpeg-devel] [RFC] Release 6.1 X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Content-Type: multipart/mixed; boundary="===============1804035182921893925==" Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" Archived-At: List-Archive: List-Post: --===============1804035182921893925== Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="qnuS/wU1MXEWeKjo" Content-Disposition: inline --qnuS/wU1MXEWeKjo Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Fri, Sep 22, 2023 at 11:32:27AM +0200, Paul B Mahol wrote: > On Fri, Sep 22, 2023 at 11:28=E2=80=AFAM Michael Niedermayer [...] > If you mean real FFmpeg work, than by all means give access to services > only you have to other > interesting parties, like security related reports and others. what ? There are 633 open issues in coverity, every FFmpeg developer can work on. i remember bringing this number down years ago to something rather small bu= t now the statistics dwarf that with the upward trend ... if you mean oss-fuzz, there are 18 tickets public about FFmpeg, anyone can = work on these https://bugs.chromium.org/p/oss-fuzz/issues/list?q=3Dffmpeg and the ffmpeg ossfuzz tickets, go to ffmpeg-security, 3 people from google, 1 from mozilla, jb and ffmpeg-security is me, reimar, ce, andreas cadhalpun, ubitux, rodger co= mbs so thats not just me and a quick count, i think i have 32 open ossfuzz issues in my inbox, with the 18 subtracted more are public with noone caring about. if we assume i fix 5 a day, what is that, 4 days of work, to fix the ones t= hat are not public. (that doesnt count ossfuzz hiding 12 issues in 62164 but yeah t= hese ive already posted fixes for i think) Also theres our bug tracker and just the normal compiler warnings if you want to work on this sort of thing where are the developers who want to work on something above but do not have access ? the only other issue i remember on ffmpeg-security thats not spam and not o= ssfuzz is a XSS issue in the fate server which i believe nicolas is working on. If someone is interrested in working on the fate server code, please come f= orth the code is in need for a maintainer outside this issue. I just had asked n= icolas about it because i did not know anyone else who knows perl and be willing to help look into a not entirely trivial (for me) issue in fate server thx [...] --=20 Michael GnuPG fingerprint: 9FF2128B147EF6730BADF133611EC787040B0FAB Everything should be made as simple as possible, but not simpler. -- Albert Einstein --qnuS/wU1MXEWeKjo Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iF0EABEIAB0WIQSf8hKLFH72cwut8TNhHseHBAsPqwUCZQ2pdgAKCRBhHseHBAsP q2myAKCa7DgWl3r1k54NDiTcFWo6DlVysACcD37f54qCCXnUx5BI0v8EhAQYQik= =FOz6 -----END PGP SIGNATURE----- --qnuS/wU1MXEWeKjo-- --===============1804035182921893925== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ ffmpeg-devel mailing list ffmpeg-devel@ffmpeg.org https://ffmpeg.org/mailman/listinfo/ffmpeg-devel To unsubscribe, visit link above, or email ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe". --===============1804035182921893925==--