Comment on Do you actually audit open source projects you download?
corsicanguppy@lemmy.ca 3 days agoI maintained an open-source app for many years. It leveraged a crypto library but allowed for different algos, or none at all for testing.
Some guy wrote a CVE about “when I disable all crypto it doesn’t use crypto”. So there’s that. It’s the only CVE we got before or during my time.
But even we got one.
petersr@lemmy.world 3 days ago
Oh damn, haha.