logoalt Hacker News

jacquesmyesterday at 5:36 PM1 replyview on HN

In theory there is no difference between theory and practice, but in practice there is.

> If they haven’t, it would be ethically dubious for you to not report it.

I can report all I want, someone needs to act on that report for it to have an effect.

There are people out there who think that some static analysis tool plugged into their CI/CD pipeline is the equivalent of a code audit.


Replies

cluckindanyesterday at 8:35 PM

But the aforementioned NIST standard requires a lot more from auditing and operations.

show 1 reply