Sebastian Raible
banner
sebastianraible.eurosky.social
Sebastian Raible
@sebastianraible.eurosky.social
Director EU Government Affairs @ APELL // Political Consultant
Reposted by Sebastian Raible
Put Open Source front and centre: APELL’s reaction to the publication of the #PublicProcurement Act and European #InnovationAct proposals. apell.info/2026/09/16/p...
Put Open Source front and centre: Public Procurement Act and European Innovation Act proposals – APELL
apell.info
September 16, 2026 at 8:52 AM
Reposted by Sebastian Raible
⏰ Just 1 hour to go till #SOTEU

Tune in here to follow President Ursula von der Leyen (@vonderleyen.ec.europa.eu ) — as she sets our her priorities for Europe in the coming year, in the European Parliament.

🔴 We’ll be streaming LIVE here from 9:00 CET - stay tuned.
September 16, 2026 at 6:14 AM
Reposted by Sebastian Raible
In den ARD-Tagesthemen bezieht DJV-Bundesvorsitzender Mika A. Beuster klar Stellung zum aggressiven Verhalten von Streamern aus dem Umfeld der AfD und bewertet Einschüchterungen und Bedrohungen gegenüber Journalist:innen als Eingriff in die Pressefreiheit.
September 15, 2026 at 8:39 AM
Big day today as we are awaiting the @ec.europa.eu publishing its proposal for a unified Public Procurement Act, alongside a new European Innovation Act. Procurement is a huge lever for #DigitalSovereignty with #OpenSource.
September 9, 2026 at 9:21 AM
It felt like coming home, when I joined @apell.info in 2024.

Today I'm announcing I will be leaving my role at APELL and continue my Free and Open Source Software journey as Ecosystem & Partnerships Manager at the DC-EDIC in November.

Read my full post here: raible.be/blog/2026/09...
Sebastian Raible – political consultant
Sebastian Raible is a political consultant for European policy in Brussels. As a computer scientist with nine years of experience in the European Parliament, he specialises in digital policy.
raible.be
September 8, 2026 at 12:21 PM
fyi, I moved my bsky handle to eurosky today, using the easy migration tool here -> help.eurosky.tech/article/9-mi...
Migrating to Eurosky
How does the migration process work exactly? Do I create a new account first and then move the old one? No, you do not need to create a new account. You can mov
help.eurosky.tech
September 1, 2026 at 12:48 PM
Reposted by Sebastian Raible
APELL is hiring! 🙋 We are excited to announce, we are looking to hire three positions, more info on our website and below in this thread.

apell.info/jobs/
August 28, 2026 at 12:16 PM
The Public Procurement Regulation proposal is coming. Is there really no Open Source #FLOSS in there, and what stands out from the leak we saw earlier in July? #PublicProcurement #OpenSource #DigitalSovereignty www.linkedin.com/pulse/policy...
Policy analysis time: the Public Procurement Regulation leak
Policy analysis time: I have finally taken the time to look into the Public Procurement Regulation proposal that leaked/floated around earlier in July, and while I concur with Diego Naranjo's first as...
www.linkedin.com
August 11, 2026 at 3:01 PM
Reposted by Sebastian Raible
"Rasterfahndung ist und bleibt verfassungs- und grundrechtswidrig, egal von wem oder welcher Software sie ausgeht. Wir haben es hier nicht nur mit einer Debatte zur Souveränität zu tun, die politischen Debatten in diesem Kontext sind daher Nebelkerzen und sollen vom eigentlichen Problem ablenken."
August 5, 2026 at 9:26 AM
Reposted by Sebastian Raible
At the end of June, we had the honour to welcome 60 guests to our annual conference!

🚀 In Utrecht at the APELL Conference 2026, we discussed EU Open Source at Scale!

In case you missed it, fresh off the (Word-)press, read our conference report now: apell.info/2026/07/27/a...
APELL Conference 2026 Report – APELL
apell.info
July 27, 2026 at 10:14 AM
Reposted by Sebastian Raible
Aufgepasst!

Ihr könnt in einer kurzen, schnellen und interessanten Umfrage Euren Senf zu den verschiedenen Design-Optionen für die neuen Euro-Geldscheine abgeben!

Auf geht's!

https://surveys.ecb.europa.eu/10b/neweuro/
July 24, 2026 at 5:25 PM
Ende August bin ich zur IT-Beschaffungskonferenz an der @bfh-ch.bsky.social eingeladen, um über die Rolle der öffentlichen Beschaffung für Digitale Souveränität zu sprechen. 🥳
#OpenSource-Unternehmen spielen eine Schlüsselrolle für Europas Wettbewerbsposition und digitale Souveränität.
July 8, 2026 at 1:28 PM
Reposted by Sebastian Raible
Join us on 30 June in Utrecht to discuss EU Open Source at Scale. There is still time to sign up, tickets are numbered! We are looking forward to welcoming you in Utrecht!
June 18, 2026 at 12:44 PM
Reposted by Sebastian Raible
Eleven days until the APELL Conference 2026 – EU Open Source at Scale! Today, we celebrate our generous sponsors - no conference without you! @owncloud.bsky.social @suse.com @collaboraoffice.bsky.social @tdforg.bsky.social Seacom @xwikisas.bsky.social
Pre-final agenda out now! apell.info/conference
June 18, 2026 at 12:44 PM
When I submitted my proposal for an @apell.info EU Policy Update to #OW2con in February, the @ec.europa.eu’s #TechSovereignty Package was expected to be published at the end of March. Things changed, so today, I presented my takeaway of the draft documents that we saw leaked last week.
🧵1/6 #ow2con
June 2, 2026 at 10:01 AM
Reposted by Sebastian Raible
Only 35 days until the APELL Conference 2026 – get your tickets while they last: apell.info/conference

🔵 Laurent Rojey, Digital Commons EDIC
🟠 Anais Concepcion, Grist
🔵 Gina Plat, NL OSPO
🟠 Jutta Horstmann, Heinlein Group
🔵 Nick Veenhof, GitLab

Gold sponsor: Collabora
May 26, 2026 at 9:33 AM
The @ec.europa.eu just announced another postponement of the long awaited #TechSovereignty package, to 3 June. #digitalSovereignty #OpenSource
May 19, 2026 at 12:44 PM
The European Commission has removed the Open Source Strategy from its latest indicative list of points to be discussed at the Commission meetings. Instead of the strategy, a new Communication has been added.

What does this mean? 🧵1/3
May 13, 2026 at 11:45 AM
Data protection, Digital Sovereignty? They're the same picture!
apell.info APELL @apell.info · May 11
The EU's high level of data protection and much lower protection in the US are the reason behind Europe's demand for #DigitalSovereignty, and the #DigitalOmnibus should not undermine our ambitions! Read our full statement: apell.info/2026/03/06/d...
May 11, 2026 at 1:46 PM
Reposted by Sebastian Raible
Mythos finds a curl vulnerability
yes, as in singular _one_. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model _Mythos_ is _dangerously good_ at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead trickle it out to a selected few companies for a while to allow a few good ones(?) to get a head start and fix the most pressing problems first, before the general populace would get their hands on it. The whole world seemed to lose its marbles. Is this the end of the world as we know it? An amazingly successful marketing stunt for sure. ## My (non-) access Part of the deal with _project Glasswing _was that Anthropic also offered access to their latest AI model to “Open Source projects” via Linux Foundation. Linux Foundation let their project Alpha Omega handle this part, and I was contacted by their representatives. As lead developer of curl I was offered access to the magic model and I graciously accepted the offer. Sure, I’d like to see what it can find in curl. I signed the contract for getting access, but then nothing happened. Weeks went past and I was told there was a hiccup somewhere and access was delayed. Eventually, I was instead offered that someone else, who has access to the model, could run a scan and analysis on curl for me using Mythos and send me a report. To me, the distinction isn’t that important. It’s not that I would have a lot of time to explore lots of different prompts and doing deep dive adventures anyway. Getting the tool to generate a first proper scan and analysis would be great, whoever did it. I happily accepted this offer. (I am purposely leaving out the identity of the individual(s) involved in getting the curl analysis done as it is not the point of this blog post.) ## AI scans of curl Before this first Mythos report, we had already scanned curl with several different very capable AI powered tools (I mean _in addition to_ running a number of “normal” static code analyzers all the time, using the pickiest compiler options and doing fuzzing on it for years etc). Primarily AISLE, Zeropath and OpenAI’s Codex Security have been used to scrutinize the code with AI. These tools and the analyses they have done have triggered somewhere between _two and three hundred_ bugfixes merged in curl through-out the recent 8-10 months or so. A bunch of the findings these AI tools reported were confirmed vulnerabilities and have been published as CVEs. Probably a dozen or more. Nowadays we also use tools like GitHub’s Copilot and Augment code to review pull requests, and their remarks and complaints help us to land better code and avoid merging new bugs. I mean, we still merge bugs of course but the PR review bots regularly highlight issues that we fix: our merges would be worse without them. The AI reviews are used _in addition_ to the human reviews. They help us, they don’t replace us. We also see a high volume of high quality security reports flooding in: security researchers now use AI extensively and effectively. Security is a _top_ _priority_ for us in the curl project. We follow every guideline and we do software engineering properly, to reduce the number of flaws in code. Scanning for flaws is just one of many steps to keep this ship safe. You need to search long and hard to find another software project that makes as much or goes further than curl, for software security. Steps involved in keeping curl secure ## May 6, 2026 It was with great anticipation we received the first source code analysis report generated with Mythos. Another chance for us to find areas to improve and bugs to fix. To make an even better curl. This initial scan was made on curl’s git repository and its master branch of a certain recent commit. It counted 178K lines of code analyzed in the src/ and lib/ subdirectories. The analysis details several different approaches and methods it has performed the search, and how it has focused on trying to find which flaws. A fun note in the top of the report says: > curl is one of the most fuzzed and audited C codebases in existence (OSS-Fuzz, Coverity, CodeQL, multiple paid audits). Finding anything in the hot paths (HTTP/1, TLS, URL parsing core) is unlikely. … and it correctly found no problems in those areas. Completely unscientific poll on Mastodon about people’s expectations for Mythos scanning curl ## The size of curl curl is currently 176,000 lines of C code when we exclude blank lines. The source code consists of 660,000 words, which is 12% more words than the entire English edition of the novel War and Piece. On average, every single production source code line of curl has been written (and then rewritten) 4.14 times. We have polished on this. Right now, the existing production code in git master that still remains, has been authored by 573 separate individuals. Over time, a total of 1,465 individuals have so far had their proposed changes merged into curl’s git repository. We have published 188 CVEs for curl up until now. curl is installed in over _twenty million instances_. It runs on over _110 operating systems_ and _28 CPU architectures_. It runs in every smart phone, tablet, car, TV, game console and server on earth. ## Five findings became one The report concluded it found **five** “Confirmed security vulnerabilities”. I think using the term _confirmed_ is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take. Five issues felt like nothing as we had expected an extensive list. Once my curl security team fellows and I had poked on the this short list for a number of hours and dug into the details, we had trimmed the list down and were left with _one_ confirmed vulnerability. The other four were three false positives (they highlighted shortcomings that are documented in API documentation) and the fourth we deemed “just a bug”. The single confirmed vulnerability is going to end up a _severity low_ CVE planned to get published in sync with our pending next curl release 8.21.0 in late June. The flaw is not going to make anyone grasp for breath. All details of that vulnerability will of course not get public before then, so you need to hold out for details on that. The Mythos report on curl also contained a number of spotted bugs that it concluded were not vulnerabilities, much like any new code analyzer does when you run it on hundreds of thousands of lines of code. All the bugs in the report are being investigated and one bye one we are fixing those that we agree with. All in all about twenty bugs that are described and explained very nicely. Barely any false positives, so I presume they have had a rather high threshold for certainty. curl is certainly getting better thanks to this report, but counted by the volume of issues found, all the previous AI tools we have used have resulted in larger bugfix amounts. This is only natural of course since the first tools we ran had many more and easier bugs to find. As we have fixed issues along the way, finding new ones are slowly becoming harder. Additionally, a bug can be small or big so it’s not always fair to just compare numbers ## Not particularly “dangerous” My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing. This is just _one_ source code repository and maybe it is much better on other things. I can only tell and comment on what it found here. ## Still very good But allow me to highlight and reiterate what I have said before: AI powered code analyzers are _significantly_ better at finding security flaws and mistakes in source code than any traditional code analyzers did in the past. All modern AI models are good at this now. Anyone with time and some experimental spirits can find security problems now. The high quality chaos is real. Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools. Mythos will, and so will many of the others. Not using AI code analyzers in your project means that you leave adversaries and attackers time and opportunity to find and exploit the flaws you don’t find. ## How AI analyzers differ * They can spot when the comment says something about the code and then conclude that the code does not work as the comment says. * It can check code for platforms and configurations we otherwise cannot run analyzers for * It “knows” details about 3rd party libraries and their APIs so it can detect abuse or bad assumptions. * It “knows” details about protocols curl implements and can question details in the code that seem to violate or contract protocol specifications * They are typically good at summarizing and explaining the flaw, something which can be rather tedious and difficult with old style analyzers. * They can often generate and offer a patch for its found issue (even if the patch usually is not a 100% fix). ## More details from the report **Zero memory-safety vulnerabilities found.** Methodology note: this review is hand-driven analysis using LLM subagents for parallel file reads, with every candidate finding re-verified by direct source inspection in the main session before being recorded. The CVE to variant-hunt mapping was built from curl’s own vuln.json. No automated SAST tooling was used. This outcome is consistent with curl’s status as one of the most heavily fuzzed and audited C codebases. The defensive infrastructure (capped dynbufs everywhere, `curlx_str_number` with explicit max on every numeric parse, `curlx_memdup0` overflow guard, CURL_PRINTF format-string enforcement, per-protocol response-size caps, pingpong 64KB line cap) systematically closes the bug classes that would normally be productive in a codebase this size. Coverage now includes: all minor protocols, all file parsers, all TLS backends’ verify paths, http/1/2/3, ftp full depth, mprintf, x509asn1, doh, all auth mechanisms, content encoding, connection reuse, session cache, CLI tool, platform-specific code, and CI/build supply chain. ## AI finds existing kinds of errors It should be noted that the AI tools find the usual and established kind of errors we already know about. It just finds new instances of them. We have not seen any AI so far report a vulnerability that would somehow be of a novel kind or something totally new. They do not reinvent the field in that way, but they do dig up more issues than any other tools did before. ## More to find These were absolutely not the last bugs to find or report. Just while I was writing the drafts for this blog post we have received more reports from security researchers about suspected problems. The AI tools will improve further and the researchers can find new and different ways to prompt the existing AIs to make them find more. We have not reached the end of this yet. I hope we can keep getting more curl scans done with Mythos and other AIs, over and over until they truly stop finding new problems. ## Credits Thanks to Anthropic and Alpha Omega for providing the model, the tools and doing the scan for us. Thanks also to the individual who did the scan for us. Much appreciated! Top image by Jin Kim from Pixabay Thanks for flying curl. It’s never dull.
daniel.haxx.se
May 11, 2026 at 6:06 AM
Reposted by Sebastian Raible
Join us on Tuesday 30 June in Utrecht (NL) for the #APELLConference 2026! Discussing EU #OpenSource at Scale!
Register for your ticket now: apell.info/conference
April 27, 2026 at 2:13 PM
Reposted by Sebastian Raible
@emilyomier.bsky.social has consulted #OpenSource projects that want to start a business. I had the opportunity of interviewing her for the @apell.info NGI0 Business Circle #podcast to talk about revenue models for communities.
See the recording now: video.ngi.eu/w/kZxcev86T7...
Revenue Models for Communities
Episode 02 of the APELL NGI0 Commons Business Circle podcast with our guest Emily Omier. The two posts we talked about during the episode: 32:09 Element: Governments need to adopt Matrix responsibl...
video.ngi.eu
April 7, 2026 at 7:20 AM
March 27, 2026 at 9:01 AM
Reposted by Sebastian Raible
🚨 News alert on the long-stalled battle to pick the EU's next privacy chief, the European Data Protection Supervisor (EDPS).

Sources tell me the Council and the EP's LIBE committee agreed on breaking the gridlock through a voting procedure also used for picking a seat for the EU Customs Agency.
March 26, 2026 at 1:48 PM