Hacker News new | ask | show | jobs
by pylua 4 days ago
This is the real answer to the op.

It’s incredible how overblown these sorts of things can become

1 comments

If the customer can run the scanner and find the vuln, that means they can log in, right? Which means they can RCE.
Not always, it can be run at static code analysis or the container repository (not the prod one)?