4 ms·
I think comparing is pointless. You are correct that a project with a small number of vulns is no more secure than the one with a high number of vulns. But coun
by f055 8y ago
I think comparing is pointless. You are correct that a project with a small number of vulns is no more secure than the one with a high number of vulns. But counting seem sensible - if a project spills major vulns at a continuous rate it means two things: the overall codebase is not improving, and who knows how many more vulns there are. It's not something to be happy about.
- staticassertion 8y agoI disagree for exactly the reasons I've stated - "more vulns" doesn't take impact into account. "More vulns" doesn't take who is reporting them into account (internal? paid pentester?). These things matter a lot. Again, look at projects that pay for vulns. They have hundreds a year - this is a good thing. They come in at a continuous rate. Counting is pointless.