3 ms·
I really learned this the hard way over the last year. My company has a client that requires all scan findings to have a plan for fixing them. No assessment is
by sethev 6y ago
I really learned this the hard way over the last year. My company has a client that requires all scan findings to have a plan for fixing them. No assessment is allowed, if the scanner reports it we have to assume it's a real vulnerability. However, you can usually just close it if the vendor says they won't fix it.
I feel like there's an opportunity for a business where you can log a ticket with them for Debian issues and they just read the security tracker page and tell you whether it will be fixed or not.