Get the latest tech news
Triaging security issues reported by third parties
I have to spend several hours each week dealing with security issues reported by third parties. Most of these issues aren't critical but it's still a lot of...
I have to spend several hours each week dealing with security issues reported by third parties. All the "best practices" like OpenSSF Scorecards are just an attempt by big tech companies to guilt trip OSS maintainers and make them work for free. It's even more unlikely with Google Project Zero, the best white-hat security researchers money can buy, breathing down the necks of volunteers.
Or read this on Hacker News