The Cal.com platform has stopped publishing code due to concerns about vulnerabilities being revealed through AI.

The developers of the scheduling and meeting automation platform Cal.com have announced the cessation of publishing the full product source code and have provided the community with a trimmed fork cal.diy, transferred from AGPLv3.0 to the MIT license. The reason for changing the development approach is attributed to the increasing risks associated with securing a SaaS platform, given the advancements in AI model capabilities for discovering vulnerabilities and writing exploits.

Whereas previously, identifying vulnerabilities and creating exploits required considerable time and was the domain of seasoned professionals, now even beginners can quickly create an exploit for a new vulnerability thanks to AI, faster than developers can write a fix. To protect the data of the cloud service built on the Cal.com platform and reduce the risk of compromise, it has been decided to stop publishing the source code of new releases.

For those who value the availability of source code, a fork cal.diy has been created, which will be maintained by the community. The fork contains only basic functionality suitable for running a meeting scheduling platform on their own. server, but lacks the capabilities offered in the full enterprise version, such as the analytics dashboard, SSO/SAML, support for teams, organizations, and workflows. Additionally, many key subsystems have been rewritten in the closed version, including authentication and data processing.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster