I am interested in the environment, politics, computers and stuff. I think the important things in the modern world computing are open source and online anonymity.
Posts
@musevg@chaos.social That is an interesting document. The simple reading of this is that the company sending the request is required to do due diligence on libcurl, and if they find a bug fix it and provide @bagder@mastodon.social with the fix.
Where, in the exercise of due diligence, the manufacturer of the product with digital elements identifies a vulnerability in a component, including in a free and open-source component, it should inform the person or entity manufacturing or maintaining the component, address and remediate the vulnerability, and, where applicable, provide the person or entity with the applied security fix.