Old operating system (offline computer) need to come online for a few minutes

OSX El Capitan
I have an offline computer running an old OSX operating system.
I would like to connect that computer to the web for a brief few minutes in order to install HomeBrew and install a newer version of rsync. I will use the comm… Continue reading Old operating system (offline computer) need to come online for a few minutes

Public registry (database or API) for known security vulnerabilities in open source software? [closed]

Is there a reliable, public registry (preferably in the form of an API) that records known security vulnerabilities in open source software?
Why would anyone want this?
I’m trying to emulate github’s dependabot on a local server. It simply… Continue reading Public registry (database or API) for known security vulnerabilities in open source software? [closed]

How can the authenticity of releases on GitHub and GitLab be ensured? Can their hashsums change?

To help ensure authenticity of packages some projects on GitHub and on GitLab add hashsums to the descriptions of the release on the Releases page.
Sometimes, at least here, the hashsum are made part of the release’s filename. Sometimes, a… Continue reading How can the authenticity of releases on GitHub and GitLab be ensured? Can their hashsums change?

Firefox pretending to update itself, but actually not doing it, and thus being a risk for security – what am I missing?

I am a long-time Firefox user and remember that usually the UAC prompt popped up when Firefox updated itself. Some months ago (or is it years?), Firefox obviously changed the way it updates itself: I didn’t see the UAC prompt since then in… Continue reading Firefox pretending to update itself, but actually not doing it, and thus being a risk for security – what am I missing?