Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Solving this problem in a generalized way is really hard.

Maybe I have a dependency on Foo which has a critical vulnerability in a feature that I don't use. I suppress the warning and all is well. Then two weeks later someone on my team decides to use that feature, not knowing that there's a problem with it. Now we're fucked, and we'll never know because the vulnerability has been suppressed.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: