mgorny-nyan (he) :autism:🙀🚂🐧<p>You know it's a good day when you turn a "this random <a href="https://social.treehouse.systems/tags/NIH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NIH</span></a> build system bundles several libraries" bug that's ignored for years into "all the bundled libraries in <a href="https://social.treehouse.systems/tags/premake" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>premake</span></a> are vulnerable" bug.</p><p><a href="https://bugs.gentoo.org/773475" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">bugs.gentoo.org/773475</span><span class="invisible"></span></a></p><p>And yes, upstream knows about <a href="https://social.treehouse.systems/tags/cURL" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cURL</span></a> at least, and doesn't do anything about it:</p><p><a href="https://github.com/premake/premake-core/issues/2156" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/premake/premake-cor</span><span class="invisible">e/issues/2156</span></a></p><p>Again, why are people using this crap!?</p><p><a href="https://social.treehouse.systems/tags/Gentoo" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Gentoo</span></a> <a href="https://social.treehouse.systems/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a></p>