|
|
|
|
|
by elorm
649 days ago
|
|
Can't tell what happened to the earlier link but I've fixed the it. Puck was being malicious in releasing the information.
There's no favourable way of describing disclosing a vulnerability on social media because the maintainers didn't meet your 7 day deadline. It's more of "we're forcing their hands since they haven't met our expectations yet" thing. There's so many ways they could've gotten a timely fix without "doing everyone a favour by not fully disclosing the entire 0 day." approach but like you said .... tough cookies all round. And to answer your final question, there's a patch available. https://github.com/NixOS/nixpkgs/pull/340885 |
|