3 ms·
Yes, this is a separate issue. jackson-databind is a XML/JSON parser so I was presuming a web stack here and that your customer wouldn't necessarily know what y
by cipherboy 7y ago
Yes, this is a separate issue. jackson-databind is a XML/JSON parser so I was presuming a web stack here and that your customer wouldn't necessarily know what your backend was. Which also means that it is up to you to secure it properly, which has its own risk.
I'd just point out that accepting any customer's policy as something you implicitly agree to support is inherently risky without an adequate contract between the relevant parties. Presumably, you've signed a contract with the customer, and if they have a no-CVE policy, there's SLAs that you can point to that say what is and isn't covered, and by what date. So it is just the price of doing business and both parties know that this'll impact the delivery of other features, bug fixes, &c. Otherwise, your business-people aren't doing a great job of covering the costs of doing business with said customer... :)
Without much better developer tooling, we'll always be trying to catch up with the people who find vulnerabilities. People aren't perfect. Tools aren't perfect either. But they can complement each other nicely and currently most projects err on the side of "too little" rather than "too much" tooling.