Sandboxed isn't safe
A security review read "safely process untrusted media" and asked the harder question. A sandbox stops escape; it does not stop exhaustion.


A security review read "safely process untrusted media" and asked the harder question. A sandbox stops escape; it does not stop exhaustion.

The documented cargo cache key gives every lockfile its own cache. On a self-hosted runner that fills the disk. Whose disk was the advice for?

A cull is worthless if it cannot follow you into Lightroom. Writing XMP sidecars out of krites, and being careful about what not to write.

The last US AVC patent expires in November 2027. Until then ffmpeg-wasi's H.264 encoder ships on sufferance, on Cisco's binaries taught to run under WASI.

A post hit Hacker News and the analytics showed pages far heavier than a static site should be. The cover images were the payload.

FFmpeg assumes a disk it can seek around in. Giving it a convincing in-memory filesystem, and testing the behaviour that would hurt most first.

Three HIGH advisories deep in a Rust dependency tree, a one-line fix that changed nothing, and eleven minor bumps that were never mine to make.

afmpeg shipped single input to single output. Adding multi-pad filter graphs and multi-output muxing: one decode, two files, one pass.

A browser will not attach a bearer token to a page navigation. Swapping the header for a cookie the framework already understood, without weakening it.

Half my CI jobs ran for no reason on every merge request. Skipping them with rules:changes, and why that is trickier than the manual suggests.
