Re: Best way to keep ourselves informed of security vulnerabilities

Andreas Beeker <[email protected]>
Newsgroups gmane.comp.jakarta.poi.user
Message-ID <[email protected]>
Hi Venkat,

> Is there a way to keep track of security vulnerabilities discovered in Apache POI? 


I know the following sources:

the official CVE list:
https://www.cvedetails.com/vulnerability-list/vendor_id-45/product_id-22766/Apache-POI.html

our change list not necessarily point out security issues:
http://poi.apache.org/changes.html

our sonar instance reports vulnerabilities:
https://sonarcloud.io/dashboard?id=poi-parent

you can verify the source commits / logs, if you like ... but usually we don't write "ATTENTION severe vulnerability" into it ...

and as every Apache project, we have a private mailing list, which is only available to committers, where every now and then (maybe once every 1/2 year), we discuss security issues.

Best wishes,
Andi
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEJBiFYFJEALFCvjOGqT4cSyYGLOMFAl6nP3cACgkQqT4cSyYG
LOMDbAf+OYEY+poLUpIrmIA6Df5M7BcwPYKnfws1qYL8tm6as49bPzILhTtcidcq
SvLXPghOOJ1TSndhTKTJ/Gf4m3954e9nD9V4jYaCD6d8MjDwA+qvMe3dpcQD9oJ+
JV5yPEGZTu47gT7kTiudXLLjo5GAxAc72e1bBe1ftIhNtzQNHuwW3EO5QKLTe7+2
n0VEdUmSaUbbwXayfJEkPP6+3y3pke1Cxf/eRAs7M3dkd5xSttnWPiwioXlLq9Ib
EpJDxhYyoOmEGal0B9/d9XTc8BQ5XJu6hRkqH49xSqcaYcqwLdjlQaxGFr0T7Eul
k5AiEFt/IhxqMHLo0zlQb2HLDOuAfQ==
=I74r
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.