Hacker News new | past | comments | ask | show | jobs | submit login

One day libfoo announces a must-fix RCE bug, which started in 1.74 and is fixed in 2.11.

Quick, which containers have libfoo in them? What version? Do you have a complete build process for them, or did you download the container from somebody else? Is it a clean libfoo, or did somebody clone it into their own tree and has later made modifications to it?

And that's really quite "annoying" from the sysadmin perspective, which makes it annoying from the devops perspective, which should make it annoying from your whole IT infrastructure perspective.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: