> Note that on a vulnerable machine, proper testing of OpenSSL would fail and should be noticed before deployment.
so is 'proper testing' included in the default build script or..?
> Note that on a vulnerable machine, proper testing of OpenSSL would fail and should be noticed before deployment.
so is 'proper testing' included in the default build script or..?
It sounds an awful lot like “you’re responsible for catching our screw-ups” and it’s a bit rich to tell people to do proper testing while the project itself failed to do so before letting this land.
To be vulnerable, you need to build on a non-vulnerable machine which passes the built in tests, then you need to deploy to a vulnerable one and finally you have to not verify that the deployment works.
Absolutely not what you are implying.
Debian for example shipped vulnerable packages: https://security-tracker.debian.org/tracker/CVE-2022-2274
If you build on an earlier machine where the tests pass and deploy to a later one and then don't check that the deployment works, you are at risk.
I think proper testing covers both options.