| ▲ | fweimer 4 days ago | |
As far as I understand it, the other efforts have not reported most of their findings to upstream developers, focusing on critical findings only. This is understandable because upstream interactions at scale are difficult. | ||
| ▲ | zamadatix 4 days ago | parent [-] | |
In the case of big projects like curl the interaction seems a bit more complete. E.g. There are some other blog posts about how the engagements and reviews worked which go decently beyond a pre-filtered dump of high severity CVE claims appearing out of the blue. | ||