AI companies have open source initiatives. But critical infrastructure that doesn't fit the small-JS-lib-with-lots-of-GitHub-stars mold gets skipped.
CC: @AnthropicAI@OpenAI@GoogleOSS your tools found real bugs in our code. Maybe help us fix the next ones before they happen?
Recently, @depthfirstlabs with AI found 21 security issues. Legit, credit where it's due, some of them were serious.
Whilst disclosure is nice, and some fixes were even sent out, like with the Mythos-found issues, the best would have been to avoid having the issues altogether.
We're an open-source project consisting of volunteer programmers, comfortable with C, assembly, and Perl.
Most of us still program by hand. It's hard to justify spending thousands a month on AI agents scanning.
We've relied on support from Coverity or Google's OSS fuzz to help.
FFmpeg is critical infrastructure for a lot of big companies.
The security-report workload is rising fast. It would be nice if donations, sponsorships, and code contributions kept pace.
@languagecyborg This is the image to redo: https://t.co/0xKSfBcfov (for a future news entry on https://t.co/44aN7MeBYo). License should be CC BY 4.0 or CC0
If we receive multiple good submissions we will do a community poll.
Ampere has clarified that the 2021/22 server was sent to VideoLAN. That server benefited the wider free software multimedia ecosystem. Ampere has also agreed to donate a server to SPI for use in FFmpeg CI. We thank Ampere for helping resolve this.
Any artists or designers in the FFmpeg community who would like to help out?
We occasionally need artwork for social media, homepage news, and other community communication. It is volunteer/unpaid, help us fight ai-slop!
Reply or mail [email protected]
So far, only 2 people have mailed us
The image that triggered this search was our rather bad server donation picture. So if you want to demonstrate your skills, a great sample would be a better image showing FFmpeg receiving a donated server.
The size difference between what random online "ICO converters" give you (15-370 KB) and what you get with a single @FFmpeg command (2.3 KB) is crazy!
ffmpeg -i favicon-32.png favicon.ico
Imagine all the disk space and traffic we're wasting because of them!
@neoscaperer whatever you like to include, but probably contact info (email/twitter/...)
a few examples of your work or a portfolio link, what kind of artwork/design you like doing, and any notes on your availability.
Ampere has clarified that the 2021/22 server was sent to VideoLAN. That server benefited the wider free software multimedia ecosystem. Ampere has also agreed to donate a server to SPI for use in FFmpeg CI. We thank Ampere for helping resolve this.