Skip to content

Comment on OpenSSL release announced for Mar 19. Fixes “high” severity security defects.parent

Comments

That's not true. We will withhold disclosure for a reasonable amount of time. 3 days is certainly reasonable.

For locally "sourced" errata, we do handle disclosure a little differently. A fix gets committed. Then a patch gets made. Then an email gets sent. That's about it. What we don't have is a secret cvs branch where we bundle up six or more vulns for disclosure all at once while our premium platinum access partners yank our chain.

Ha, I was close on my estimate.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.