Damus
Thomas Depierre · 5w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0ujnx96rzj2m7kl9yqhyplqhxuf55el43gdqw8xxpm7pdk3ph6gqwfaz86 Here is my pov as a maintainer. I agree with a lot of your options, but I think they will take a long time to actually hit. Because shipping continuously is going to need massive rethin...
Marcus Rohrmoser 🌻 · 5w
Hi nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0ujnx96rzj2m7kl9yqhyplqhxuf55el43gdqw8xxpm7pdk3ph6gqwfaz86, IMO #responsibility is with the #operators. They can mitigate, monitor, patch and fund. They do fund, right? If not, what's the expectation again?
Edwin Török · 5w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0ujnx96rzj2m7kl9yqhyplqhxuf55el43gdqw8xxpm7pdk3ph6gqwfaz86 I think that when the title, or CWE of a vulnerability and a package name is publicly known it should be assumed that the actual vulnerability is easily rediscoverable. Maybe at that poi...
Andrew Nesbitt · 4w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0ujnx96rzj2m7kl9yqhyplqhxuf55el43gdqw8xxpm7pdk3ph6gqwfaz86 working on an ocaml runner profile for you: https://github.com/alpha-omega-security/scrutineer/pull/901