BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//CERN//INDICO//EN
BEGIN:VEVENT
SUMMARY:When the robots came for our parsers: GStreamer security in the ag
 e of LLMs
DTSTART;VALUE=DATE-TIME:20261011T134500Z
DTEND;VALUE=DATE-TIME:20261011T141500Z
DTSTAMP;VALUE=DATE-TIME:20261010T011453Z
UID:indico-contribution-599@indico.freedesktop.org
DESCRIPTION:Speakers: Sebastian Dröge (Centricular Ltd)\nIn the last mont
 hs\, there has been a lot of reporting on LLM-based tooling easily finding
  dozens of security vulnerabilities in open source software. Projects like
  the Linux kernel or curl are well known to have been hit by this heavily\
 , with many discussions about the usefulness and validity of these reports
  and how this flood of reports can be handled. As GStreamer is used in man
 y safety critical areas and has to handle all kinds of complex data format
 s coming from untrusted sources\, GStreamer is a natural target and affect
 ed by this as well.\n\nJust this year alone >80 security vulnerabilities w
 ere already fixed while in the previous years we only had a handful of sec
 urity vulnerability reports to process.\n\nThis talk will give an overview
  of what the situation looks like nowadays for GStreamer: what kind of rep
 orts come in and which areas are affected most\, how many of the reports a
 re false positives or of low quality\, how we process them\, and how are w
 e trying to improve the situation for the future.\n\nhttps://indico.freede
 sktop.org/event/14/contributions/599/
LOCATION:Impact Hub Prague
URL:https://indico.freedesktop.org/event/14/contributions/599/
END:VEVENT
END:VCALENDAR
