Re: RFC: Adding a SECURITY.md document to the Binutils
Richard Earnshaw via Binutils <[email protected]>
| Newsgroups | gmane.comp.gnu.binutils,gmane.comp.gdb.devel |
|---|---|
| Message-ID | <[email protected]> |
On 14/04/2023 13:43, Siddhesh Poyarekar wrote: > They key is in what a project can feasibly guarantee and IMO the > binutils project is not in a position to guarantee this level of > security. By putting this into SECURITY.md, we'll be signing ourselves > (and downstream maintainers) up for much more than they can handle. No, that's covered by the warranty: GNU tools come with no warranty ... What it is about is what we would do if such a vulnerability were discovered. R.