3 ms·
From the linked thread "I have updated a new 1.0.21 release and removed the unused sig driver file. And I also add a README document about the httpdisk driver
by AnotherGoodName 11mo ago
From the linked thread
"I have updated a new 1.0.21 release and removed the unused sig driver file. And I also add a README document about the httpdisk driver https://github.com/ventoy/PXE/tree/master https://github.com/ventoy/PXE/tree/master"
So he fixed the issue, noted the use of WKDTestCert and links to it and he also has a post explaining why this happened.
That doesn't seem lackluster or negligent to me?
- i4qpLmoptUph3fZ 11mo agoEchoing similar comments on this thread. The action in itself is mildly concerning, but the lack of foresight to see this as an issue people would want to know about, and ultimately be able to make their own decision on if they want to accept that risk or not. "So I thought that maybe user don't want to care about this intermediate process" Choosing to include an unverified build from a third party in a project like this introduces significant risk. Also.. anyone know why my original comment got flagged?