Or a reasonable security posture. Unless there is a vulnerability in the current version, why scramble to update? And if the author:
1. claims they do not have access to the signing account
2. Recently said that they are not planning any important release in the next 60 days
Then I would claim that rushing to update is plain reckless. But move fast and break things, I guess
You're talking about security to people that give root access to their LLM
zx2c4 updated their post after getting access:
https://x.com/edgesecurity/status/2042185546152161474
It's currently the #2 story on this website: https://news.ycombinator.com/item?id=47719942