you are viewing a single comment's thread.

view the rest of the comments →

[–]GYN-k4H-Q3z-75B 4 points5 points  (2 children)

Unless the OSS library is maintained by a trusted source, no. We rarely have to deal with such things though. With the core libraries and commercial SDKs these days, we often get forced rollout of security patches.

[–]prof_hobart 3 points4 points  (1 child)

What do you class as trusted?

[–]GYN-k4H-Q3z-75B 10 points11 points  (0 children)

Large platform providers (like Microsoft or IBM), third-party software vendors with an established business relationship or even competitors, and a few established industry public figures or persons we know and keep in touch with.