removed by mod
fedilink
1.62K
andrew
link
fedilink
English
44
edit-2
2Y

And to a large extent, there is automatic software that can audit things like dependencies. This software is also largely open source because hey, nobody’s perfect. But this only works when your source is available.

@[email protected]
link
fedilink
English
62Y

Except when people pull off shit like Heartbleed.

andrew
link
fedilink
English
112Y

See my comment below for more of my thoughts on why I think heartbleed was an overwhelming success.

And you help make my point because openssl is a dependency which is easily discovered by software like dependabot and renovate. So when the next heartbleed happens, we can spread the fixes even more quickly.

@[email protected]
link
fedilink
English
32Y

Enterprise software inventory can unfortunately be quite chaotic, and understanding the exposure to this kind of vulnerability can take weeks if not longer.

Create a post

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.
  • 1 user online
  • 828 users / day
  • 79 users / week
  • 904 users / month
  • 2.75K users / 6 months
  • 0 subscribers
  • 2.97K Posts
  • 31.5K Comments
  • Modlog