(no title)
dannyallan | 1 year ago
Snyk does follow a responsible disclosure policy and while no one picked this package up, had anyone done so, we would have immediately followed up with them.
dannyallan | 1 year ago
Snyk does follow a responsible disclosure policy and while no one picked this package up, had anyone done so, we would have immediately followed up with them.
luma|1 year ago
In response, you suggest that you'll send a letter of apology to the funeral home of anyone that got hit. Compromising their credentials, even if you have "good intentions", still puts them into a compromised position and they have to react the same as they would for any other malevolent attacker.
This is so close to "malicious" that it's hard to perceive a difference.
edit: Let's also remind everyone that a Snyk stakeholder is currently attempting to launch a Cursor competitor, so assuming good intentions is even MORE of a stretch.
senorrib|1 year ago
yabones|1 year ago
etyp|1 year ago
guappa|1 year ago
https://snyk.io/blog/snyk-security-labs-testing-update-curso...
austinkhale|1 year ago
pizzalife|1 year ago
unknown|1 year ago
[deleted]