3 ms·
If you discover a vulnerability in OpenSSL, are you required to track down and separately notify every downstream packager of OpenSSL? Or do you rely on the Op
by marshray 5mo ago
If you discover a vulnerability in OpenSSL, are you required to track down and separately notify every downstream packager of OpenSSL?
Or do you rely on the OpenSSL project to work their established process?