Post #1860143
2026-05-01 17:58 UTC
@davidism Of course, the human in the loop (the reporter, NOT the maintainer) SHOULD be the one comparing the outputs to the security model you've documented. I suspect the same folks who are /only now/ emboldened to scan OSS repositories for vulnerabilities aren't likely to read security policies.
Replies (0)
No replies.