Skip to content

Comment on We eliminated 1,400 CVEs in NanoClaw's container imagesparent

Comments

Are these real findings, or a situation in which fixes have been backported? At one place I worked, the corpsec guys were wildly incompetent and would try to bury me in "CVEs" in my systems that were nothing but "vulnerable" software versions with all of the "identified" vulnerabilities fixed by Debian backported patches.

Most modern scanners know the backported versions for the major vendors (ubuntu/debian/rhel/alpine), but it was definitely an issue a decade ago.

That’s not security, it’s compliance.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.