top | item 30598186

(no title)

hvidgaard | 4 years ago

I think you missed my point. Attackers will go through commits regardless of a "Security Patch" tag.

But going about your normal patch cycle as normal for things not labelled "Security Patch", just means if the patch for some reason should have been tagged but wasn't, you're in the same situation.

I do see the value in your approach, but it just does not change anything for applications where security is top priority.

discuss

order

No comments yet.