open source and code review
open source and code review
Posted Nov 11, 2024 20:01 UTC (Mon) by ballombe (subscriber, #9523)Parent article: The top open-source security events in 2024
The whole open source methodology is predicated on code review.
The detection of the xz backdoor was an effect of the open source methodology and cannot be dismissed as an artifact, so equating it with the crowstrike event is not entirely fair.
How much one is able to reduce a risk is a measure of success.
The detection of the xz backdoor was an effect of the open source methodology and cannot be dismissed as an artifact, so equating it with the crowstrike event is not entirely fair.
How much one is able to reduce a risk is a measure of success.
