Comment on FFmpeg to Google: Fund Us or Stop Sending Bugs

<- View Parent
Taldan@lemmy.world ⁨1⁩ ⁨day⁩ ago

The truth can absolutely be a bad thing. If google reports an important vulnerability, then buries it in CVE slop for 90 days, and publicly announces details of the important vulnerability that hasn’t been fixed yet, it would be worse than if they had never reported it

The 90-day publishing window is tough when OSS projects are getting buried in AI slop reports

source
Sort:hotnewtop