Opensource folks: Has anyone heard of OSS maintainers (other than presumably the log4j folks) without major corporate ties who have been invited to this?
bloomberg.com/news/articles/20

Follow

@obra I would like to get more into developing open source but if a security researcher comes with a bug. I would like to know the best processes that we can use to fix the issue and push it out so the log4j incident doesn't repeat.

· Librem Social · 1 · 0 · 0

@dean @obra in Germany it's illegal to find such a vulnerability in many cases. So you better contact yor local hacker space or the #ccc for en.wikipedia.org/wiki/Responsi

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml