Hacker News new | ask | show | jobs
by macintux 1330 days ago
It seems unlikely to me that the maintainers are that careless.
1 comments

It is the norm for the patch to be committed and the CVE to be acquired as part of that process.
Yep, per this comment my optimism was misplaced.

https://news.ycombinator.com/item?id=33384596

Or, it appears I may have been correct the first time.

https://news.ycombinator.com/item?id=33382684

That's cool. Some projects do that, some do not.