Opensource folks: Has anyone heard of OSS maintainers (other than presumably the log4j folks) without major corporate ties who have been invited to this?https://www.bloomberg.com/news/articles/2021-12-23/white-house-extends-invitation-to-improve-open-source-security
@obra I would like to get more into developing open source but if a security researcher comes with a bug. I would like to know the best processes that we can use to fix the issue and push it out so the log4j incident doesn't repeat.
@dean @obra in Germany it's illegal to find such a vulnerability in many cases. So you better contact yor local hacker space or the #ccc for https://en.wikipedia.org/wiki/Responsible_disclosure
Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy. Stay safe. Please abide by our code of conduct. (Source code)
@dean @obra in Germany it's illegal to find such a vulnerability in many cases. So you better contact yor local hacker space or the #ccc for https://en.wikipedia.org/wiki/Responsible_disclosure