Global Feed Post Login
Replying to Avatar Jameson Lopp

That feeling when you get a vulnerability report for a software library used in your project and the suggested remediation is "none" because no one has patched the vulnerability.

Second place is when the suggested remediation is "none" because other software dependencies have conflicts that prevent you from updating to a patched version.

Avatar
Elephant in the root 2y ago

At least you can patch it yourself. If it was closed source you wouldn't be able to.

Reply to this note

Please Login to reply.

Discussion

No replies yet.