3 ms·
Problem with CVEs on OSS Projects
- rymurr 2y agoArticulate post on the problems with bogus CVEs
- __s 2y agoProbably best to link to specific comment: https://github.com/micromatch/micromatch/issues/264#issuecomment-2304709335 https://github.com/micromatch/micromatch/issues/264#issuecom...
- adamgordonbell 2y agoFrom issue: * Checkmarkx (security vendor) reported bogus cve in april / may * Maintainers didn't agree the cve was real so they ignored it * Snyk and other automated scanners start harassing users about the cve * Users are annoyed by scanners and scary messages from all kinds of tools * Users start messaging devs, also devs of dependent packages which use micromatch * Hundreds, maybe thousands of hours are wasted In the end, the situation erodes trust into automated scanners. This is "a boy who've cried wolf" type of situation. When useless vulnerabilities get promoted, it's easy to lose track of something more important. Besides automated scanners, checkmarx should also be held responsible for this waste of everyone's time.
- rurban 2y agoThat's why I had to a special Invalid CVE tag to some issues: https://github.com/LibreDWG/libredwg/issues?q=is%3Aissue+label%3A%22invalid+CVE%22+is%3Aclosed https://github.com/LibreDWG/libredwg/issues?q=is%3Aissue+lab... Reporters barely can read nowadays and CVE centers neither.