Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
vrighter
31 days ago
|
parent
|
context
|
favorite
| on:
Package managers need to cool down
they run it throuh a tool that checks online whether any cves relate to that version. They don't care whether you actually hit the vuln, if there's a cve it's "bad". That's usually the level i see.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: