4 ms·
I wonder if there’s a business model around sharing the results of security reviews. Even if Company A can’t fully trust the review of Company B, you could A
by devoutsalsa 3y ago
I wonder if there’s a business model around sharing the results of security reviews. Even if Company A can’t fully trust the review of Company B, you could A could provide a lot of context for B to reduce the cost of starting an evaluation from zero.
- pylua 3y agoUsually it is just rubber stamping the results of a tool like black duck, Vera code , or any scanner and the ongoing maintenance around that. Not to mention how you configure the open source also affects if you could be vulnerable to a cve.