Re: Best way to keep ourselves informed of security vulnerabilities
Andreas Beeker <[email protected]>
| Newsgroups | gmane.comp.jakarta.poi.user |
|---|---|
| Message-ID | <[email protected]> |
Hi Venkat, > Is there a way to keep track of security vulnerabilities discovered in Apache POI? I know the following sources: the official CVE list: https://www.cvedetails.com/vulnerability-list/vendor_id-45/product_id-22766/Apache-POI.html our change list not necessarily point out security issues: http://poi.apache.org/changes.html our sonar instance reports vulnerabilities: https://sonarcloud.io/dashboard?id=poi-parent you can verify the source commits / logs, if you like ... but usually we don't write "ATTENTION severe vulnerability" into it ... and as every Apache project, we have a private mailing list, which is only available to committers, where every now and then (maybe once every 1/2 year), we discuss security issues. Best wishes, Andi
signature.asc
(application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEJBiFYFJEALFCvjOGqT4cSyYGLOMFAl6nP3cACgkQqT4cSyYG LOMDbAf+OYEY+poLUpIrmIA6Df5M7BcwPYKnfws1qYL8tm6as49bPzILhTtcidcq SvLXPghOOJ1TSndhTKTJ/Gf4m3954e9nD9V4jYaCD6d8MjDwA+qvMe3dpcQD9oJ+ JV5yPEGZTu47gT7kTiudXLLjo5GAxAc72e1bBe1ftIhNtzQNHuwW3EO5QKLTe7+2 n0VEdUmSaUbbwXayfJEkPP6+3y3pke1Cxf/eRAs7M3dkd5xSttnWPiwioXlLq9Ib EpJDxhYyoOmEGal0B9/d9XTc8BQ5XJu6hRkqH49xSqcaYcqwLdjlQaxGFr0T7Eul k5AiEFt/IhxqMHLo0zlQb2HLDOuAfQ== =I74r -----END PGP SIGNATURE-----