top | item 37406353

(no title)

freework | 2 years ago

The solution to this problem is to require the submitter to include a unit test that demonstrates the problem along with the CVE. If the unit test succeeds in DDosing or whatever, then the CVE is published. If your unit test fails to produce the security problem, then it is ignored.

discuss

order

bostik|2 years ago

In other words, PoC || GTFO for all submissions?

ticviking|2 years ago

Ultimately "Show me the code" is the only standard that has ever worked for Open Source.

Give me code to reproduce an issue for people who are contributing as developers.

bkallus|2 years ago

This works only for programs that are publicly available.