Live data from Hacker News

Nginx Security Advisory

mailman.nginx.org

1–10 of 27 posts

Re: Nginx Security Advisory

#6

Interesting, this is just an hour before the core dev quit because of disagreements on how security is managed at F5. https://news.ycombinator.com/item?id=39373327

And to be clear, the disagreement appears to be that he did not want the CVE to be assigned.

Re: Nginx Security Advisory

#7

Interesting, this is just an hour before the core dev quit because of disagreements on how security is managed at F5. https://news.ycombinator.com/item?id=39373327

And to be clear, the disagreement appears to be that he did not want the CVE to be assigned.

This has been an issue in the past, where NGINX disagreed with a CVE being assigned, but a CVE is the easiest way to get a vulnerability fixed across the ecosystem and in the distributions that distribute NGINX.

Each time something is silently fixed it takes much longer and is much harder to actually get the fix approved/backported/whatever is necessary to get it fixed.

Re: Nginx Security Advisory

#8

Interesting, this is just an hour before the core dev quit because of disagreements on how security is managed at F5. https://news.ycombinator.com/item?id=39373327

And to be clear, the disagreement appears to be that he did not want the CVE to be assigned.

source?
Post reply on HN