@stefano same (lack of) rationale when software editors are required to upgrade any dependency known to have a CVE - no matter if it is actually vulnerable or not. Vulnerability scanners drive the security. At some point they do more harm than good.
Top-level
@stefano same (lack of) rationale when software editors are required to upgrade any dependency known to have a CVE - no matter if it is actually vulnerable or not. Vulnerability scanners drive the security. At some point they do more harm than good. 2 comments
|
@jotak in my own experi nice, I agree; they did more harm than good