|
|
Subscribe / Log in / New account

Adding auditing to pip

Adding auditing to pip

Posted Aug 16, 2022 13:52 UTC (Tue) by amarao (guest, #87073)
In reply to: Adding auditing to pip by kleptog
Parent article: Adding auditing to pip

It's not about specific warnings, it's about culture. Basically, you have 'security guy' (with background from, f.e., police or some other non-IT) who was tasked with 'IT-security'. It follows the guidelines and trainings which says 'no vulnerabilities above 6.7 should be in production systems', and there is '7.4' for vulnerability which is not a vulnerability at all. There is no procedure to make it not-a-vulnerability. You explain the reason for ignoring and guy just ignore you (like police officer ignoring explanation for speeding at ticket time). The rules says 'NO VULNERABILITIES ABOVE 6.4 AND YOU HAVE 7.4 ON MY VUN-READER, DOCUMENTS PLEASE'. And there is a way to make this guy quiet. Install package in a way which is not visible for scanner, and you are fine to go (even if you have poodle with heartbleed).

If there is CVE out there, how to make it 'not CVE'? I know no such process.


to post comments

Adding auditing to pip

Posted Aug 17, 2022 0:31 UTC (Wed) by pabs (subscriber, #43278) [Link]

CVEs can be disputed, you see this all the time if you follow CVE feeds. This is mentioned in the CVE docs on at least these two pages:

https://nvd.nist.gov/general/cve-process
https://nvd.nist.gov/vuln/vulnerability-status


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds