- Sources: primary, discussion
- Summary: The OpenSSH 10.5 release notes record three security fixes. The stated reason for the cadence change is independent rediscovery: the project says it has seen a number of cases where a security bug identified by AI tools was subsequently found independently by a different researcher, which it reads as evidence that adversaries who do not report bugs can reach the same bugs, and on that basis the team will for now make more frequent releases. The same notes state that many AI reports are determined not to have security impact when considered against a realistic threat model.
- Why it matters: OpenSSH sits on nearly every server and developer machine, and the project is changing how often it ships rather than only commenting on report volume.
- Follow-up: Whether the stated cadence holds, and what the next releases carry.
send feedback on this story