Android app developer.

GitHub
Mastodon

  • 2 Posts
  • 34 Comments
Joined 1 year ago
cake
Cake day: June 9th, 2023

help-circle














  • The cool thing about software is that it can be updated, so if someone finds a vulnerability and follows the proper CVE disclosure process, instance admins can just update immediately when it’s disclosed.

    I guess it’s a little trickier because open source software can’t really say “fix a vulnerability that hasn’t been disclosed yet” in a commit message without disclosing the bug, and instances can’t just be silently updated before disclosure, but I’m sure there are other ways to handle CVEs that don’t rely on information obfuscation.