|
|
|
|
|
by pentesterlab
3597 days ago
|
|
Quick answer: get a better auditor. Long answer: it's a risk game, you may get away by showing that you have processes in place to manage this risk for open source projects:
* internal backup of the source tree.
* in-house skills to perform basic patching of the software if the development get discontinued.
* alternative solution and roll-out plan in case the development of your current solution gets discontinued.
* ... Finally, risks can be accepted and someone ("the business") can sign-off on them. You don't have to remediate everything. It's just an awareness exercise for "the business". |
|
If however its a more general/vague concern about OSS support then you'll have a hard time dealing with it and acceptance may be the appropriate route.