And CVE's: People actually do that now, which before they didn't. Github allowing it now, certainly does help massively. This is a good thing
And CVE's: People actually do that now, which before they didn't. Github allowing it now, certainly does help massively. This is a good thing
No doubt is it a good thing to have issues reported and fixed, but CVE feels a bit like blackmailing maintainers - either you fix the issue or we get your project flagged with "security scanners".
I guess, my distaste mostly originates from randomly assigned high CVE numbers that don't reflect the actual threat. And the fact that it gives the companies which use the code "AS IS" an imaginary stick to hit open source maintainers, until they fix the issues for the company (for free of course).
Which was certainly an improvement, given that Github is in no hurry to add modules support to CodeQL.