NEWS: @Google funds Linux kernel developers to focus exclusively on security: https://bit.ly/3pUnrL4 #linux #linuxkernel #security #supplychain #oss @nathanchance
-
-
W odpowiedzi do to @linuxfoundation@CloudNativeFdn i jeszcze
Serious question: Does that mean there's a chance Linux will do proper CVE, marking of releases, etc going forward? Last time I looked, it was still the fundamentally wrong "SeCuRiTy BuGs ArE lIkE aLl OtHeR bUgS" game.
1 odpowiedź 0 podanych dalej 3 polubione -
W odpowiedzi do to @TwitchiH@linuxfoundation i jeszcze
At the Linux kernel level, yes, they still treat all bugs as potential security vulnerabilities.
@gregkh can explain why better than I can.1 odpowiedź 0 podanych dalej 1 polubiony -
W odpowiedzi do to @mdolan@linuxfoundation i jeszcze
I meant the inverse of Linus arguing that security fixes don't need to be marked specifically which makes downstream work and upgrades needlessly hard.
2 odpowiedzi 0 podanych dalej 0 polubionych -
"downstream" only has to take the weekly stable/LTS releases to get all known security and bug fixes (i.e. security fixes we don't know about yet). How much easier can it get for them, we provide it all fully tested!
2 odpowiedzi 1 podany dalej 4 polubione
Companies have verified over the years that taking these releases means that all published CVEs are fixed _before_ they are announced, given that the average CVE request-to-release is -100 days (meaning the fix has been public for 100 days before the CVE was asked for.)
Wydaje się, że ładowanie zajmuje dużo czasu.
Twitter jest przeciążony lub wystąpił chwilowy problem. Spróbuj ponownie lub sprawdź status Twittera, aby uzyskać więcej informacji.