|
|
|
|
|
by TheDong
236 days ago
|
|
> so is still a bug and should still get a CVE It's a bug, sure. The V in CVE is for "vulnerability", which is why people treat CVEs as more than just bugs. If every bug got a CVE, practically every commit would get one and they'd be even less useful than they are now. At that point, why not just use commit hashes for CVEs and get rid of the system entirely if we're going to say every bug should get a CVE? > Re: Harassment - Can't the project release a statement saying that the bug writeup is low quality and unable to be reproduced? If your suggested response to a human DoS is "why can't the humans just do more work and write more difficult-to-word-correctly communication", then you're not understanding the problem. |
|
I imagine the response would be looking at it briefly, seeing if it looks dangerous or reproducible and getting an AI to return a templated "PoC or GTFO" response.
The mere existence of a CVE doesn't tell anyone whether a bug is valid or not, and the security reports should be handled in the same way regardless of whether one does exist. For some odd reason people have attached value to having your name logged beside CVEs, despite it not telling you anything,