3 ms·
In an ideal universe yes. But we live in a world where vulnerability scanners reign supreme.
by cpuguy83 3mo ago
In an ideal universe yes. But we live in a world where vulnerability scanners reign supreme.
- jamesfinlayson 3mo agoYep, I've updated dependencies with an RCE that can't be exploited in my codebase just to keep my security team happy. Not worth the multiple arguments about it not actually being an issue.
- StrauXX 3mo agoYou can never guarantee that the codepath of a dependency that is vulnerable can not be reached or used as a gadget in an exploit chain. Patching dependencies, even when no direct vulnerability arises is an essential part of defense in depth and sevurity hygene.
- sass_muffin 3mo agoYou can also never guarantee the patched software doesn't include a worse vulnerability, I would submit that patching software without proper time to validate changes is also a security issue. If you aren't careful, that is how you get this security theater.
- jamesfinlayson 3mo agoI don't disagree, though I should have been more specific - I updated dependencies at extremely short notice because that's what security wanted. I would have updated the dependencies sooner or later anyway because I know that periodically updating dependencies is generally a good thing to do.