Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you fork a dependency and change features, the CVE information on original depenency is now no longer valid for your code. Your additions or removals can induce new CVEs, or render CVE for original lib a moot point.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: