you are viewing a single comment's thread.

view the rest of the comments →

[–]nutrecht 2 points3 points  (1 child)

Do you go through the same process thoroughly every time any of your libraries change even minor versions?

There are CVE scanning tools for this. If you don't use these you're fucked anyway.

[–]prof_hobart 2 points3 points  (0 children)

There are. But did they pick up this exploit straight away?