logoalt Hacker News

SkyPuncheryesterday at 4:08 PM1 replyview on HN

This works until you consider regular security vulnerability patching (which we have compliance/contractual obligations for).


Replies

Nextgridyesterday at 7:01 PM

This only makes sense for vulnerabilities that can actually be exploited in your particular use-case and configuration of the library. A lot of vulns might be just noise and not exploitable so no need to patch.

show 1 reply