News [LWN.net] [$] Forgejo "carrot disclosure" raises security questions

News

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,739
Reaction score
74
Credits
-1,257
An unusual, some might say hostile, approach to disclosing an alleged remote-code-execution (RCE) flaw in the Forgejo software-collaboration platform has sparked a multifaceted conversation. A so-called "carrot disclosure" in April has raised questions about the researcher's methods of unveiling a security problem, Forgejo's security policies, and the project's overall security posture.

Source: https://lwn.net/Articles/1071499/

Aggregated via Linux News
 


Follow Linux.org

Members online


Top