Tweet by KentonVarda

July 10, 2026

Feeling the pain a bit of the deluge of AI security reports on Cap'n Proto. 10 bugs reported in the last three months, which is more than the entire 13-year history of the project before that. None that are extremely critical (I think) but there are some near misses. Be sure to upgrade to release 1.5 (or to tip of the v2 branch) if you use it. Don't get me wrong, I'd much rather have bugs reported and fixed than not reported. But it's a lot of work. Although the Cloudflare Workers team heavily uses and contributes to Cap'n Proto, I still technically own it as a personal project and have been personally responsible for releases and security advisories. That used to work perfectly fine, I spent like two days a year on it... but I think it might not be viable anymore. It's a lot of work to write up every bug, request a CVE, etc. Rules say you must issue a separate advisory and get a separate CVE for every bug, but I just don't have time, so I issued a rollup advisory with no CVEs. Sorry. Gonna have to figure out something new going forward. Ideally the whole process could of course be automated with AI, but then I have to spend time setting up that automation, including prompting it to write advisories in a way that doesn't suck, which I... also don't have time to do right now, too much going on. https://t.co/5Wc23RacE8

Author
KentonVarda
Date
July 10, 2026