NEWS: @Google funds Linux kernel developers to focus exclusively on security: https://bit.ly/3pUnrL4 #linux #linuxkernel #security #supplychain #oss @nathanchance
-
-
Companies have verified over the years that taking these releases means that all published CVEs are fixed _before_ they are announced, given that the average CVE request-to-release is -100 days (meaning the fix has been public for 100 days before the CVE was asked for.)
Dziękujemy. Twitter skorzysta z tych informacji, aby Twoja oś czasu bardziej Ci odpowiadała. CofnijCofnij
-
-
-
And if you want to know more about why CVEs are totally broken, especially for a project like the kernel, see my hour long talk: https://kernel-recipes.org/en/2019/talks/cves-are-dead-long-live-the-cve/ …
-
Given that upgrading is not always painless, knowing if a currently-used version is secure for a specific use case is still valuable as it can help defer non-essential upgrades. That being said, I will put your talk onto my backlog and honestly look forward to watching it.
- Pokaż odpowiedzi
Nowa rozmowa -
Wydaje się, że ładowanie zajmuje dużo czasu.
Twitter jest przeciążony lub wystąpił chwilowy problem. Spróbuj ponownie lub sprawdź status Twittera, aby uzyskać więcej informacji.