Hacker News new | ask | show | jobs
by eSandwich8 1021 days ago
This and the strange cURL CVE suggest it's a good time for vulnerability scanners to support VEX. Package publishers or users of vulnerability scanners can create VEX documents which would help prevent their releases and so on from being blocked on these kinds of CVEs.