4 ms·
The solution to this problem is to require the submitter to include a unit test that demonstrates the problem along with the CVE. If the unit test succeeds in D
by freework 3y ago
The solution to this problem is to require the submitter to include a unit test that demonstrates the problem along with the CVE. If the unit test succeeds in DDosing or whatever, then the CVE is published. If your unit test fails to produce the security problem, then it is ignored.
- bostik 3y agoIn other words, PoC || GTFO for all submissions?
- ticviking 3y agoUltimately "Show me the code" is the only standard that has ever worked for Open Source. Give me code to reproduce an issue for people who are contributing as developers.
- bkallus 3y agoThis works only for programs that are publicly available.