Hacker News new | ask | show | jobs
by rukuu001 1651 days ago
I did this years ago with an open-source and reasonably popular non-Apache library. The results were so horrifying my boss quickly concluded such audits were outside our responsibility and the time I spent on the audit was written off.

It was especially difficult for us because we’d shipped so much code that used the library, and replacing the library was unthinkable.

1 comments

Don't ask a question if you won't like the answer.