Hacker News new | ask | show | jobs
by bcassedy 1002 days ago
That same management is the type to set rules where you don't get to assess if you're vulnerable, you just have to fix all the CVEs
1 comments

And where if you beg them to allow code review (especially for the code made by your incompetent offshore teams) they say it's too expensive/uses too much developer time, but then they'll pay a subscription for garbage static analysis tools that's enough to cover multiple full time dev salaries.

Speaking purely hypothetically, of course.