progandy@feddit.detoTechnology@lemmy.ml•Dev rejects CVE severity, makes his GitHub repo read-only
9·
4 months agoThis sort of thing is the reason that the kernel has its own cve authority / cna now.
This sort of thing is the reason that the kernel has its own cve authority / cna now.
It’s interesting, that it would be hard to make a case that there was a “vulnerability” in the
ip
package. But it seems like this package’s entire purpose is input validation so it’s kind of weird the dev thinks otherwise.
Yes, input validation, probably for forms. What the Dev disputes is that he cannot see a case where it is used in a security critical way where
deleted by creator
“Protecting our community," by destroying it. If you don’t have a community, then it can’t be toxic. Were the comments so bad that this was the only solution?