Hacker News new | ask | show | jobs
by ArchOversight 857 days ago
This has been an issue in the past, where NGINX disagreed with a CVE being assigned, but a CVE is the easiest way to get a vulnerability fixed across the ecosystem and in the distributions that distribute NGINX.

Each time something is silently fixed it takes much longer and is much harder to actually get the fix approved/backported/whatever is necessary to get it fixed.

1 comments

Except that no one is shipping with QUIC enabled. It's marked as experimental, so if you are deploying on prod you are asking for it.
Asking for what?