▲ | shortrounddev2 6 days ago | |||||||
Absolute theater. They do nothing to validate that you are compliant with whatever ISO cert you're pursuing. They make you install a root cert on your macbook and they say that's good enough to ensure compliance. You just attest that you don't do stupid shit like committing directly to master or testing in production and they believe you | ||||||||
▲ | dathinab 6 days ago | parent | next [-] | |||||||
> compliant with whatever ISO cert you're pursuing ISO cert compatibility audits are very different from a proper security audit. And weather they do anything to check if depends on which you high, many of the slightly more expensive ones have the reputation to be "fast" and "overlook most issues". But that doesn't apply to all security audits (but most audits for ISO compatibility, like really it's bad). Anyway see my way to long answer about the on a sibling comment. | ||||||||
| ||||||||
▲ | UK-AL 6 days ago | parent | prev [-] | |||||||
People test in production in all the time via Canary releases. |