So I am a bit confused on this one. Why does this particular developer or anyone really, disagree with assigning CVEs to releases code? I mean I get that it is experimental but having associated CVEs adds to disclosure on the experimental features. What is the downside of the assigned CVEs? I was all ready to jump on F5 being wrong but it sounds like they may have taken the right position. Can someone elaborate on why that may not be the case?
post
So the team were actually having a serious discussion this afternoon.
Is the new project called:
- Free-en-jin-ex
- Freen-ginks
- Free-ne-ginks
- something else
They should parse it the same way as "postgresql".
You mean "Postgres"?
shh
I call it this every chance I get because its like nails on a chalkboard to many DBAs.
edit: huh. both my clients have spoiler tags, but both are apparently broken. I can't decipher what Lemmy wants me to do for the markdown to fix it, probably the client not displaying it right.
edit 2: yeah, it looks correct on the default browser interface, but both apps I use (Boost for Lemmy and Eternity) fail to render a spoiler.
Your spoiler tag works fine on the web client. That is the supported way to do spoilers on Lemmy. However, Sync, if you use that doesn't support Lemmy spoilers and only supports reddit spoilers. Unfortunately no matter what spoiler method you use, it will not work for someone, somewhere. There is no unified spoiler markup across the fediverse, but there really should be.
Assuming they keep the upstream pronunciation theory, I think it would be: fringe-n-x
This is the best summary I could come up with:
A core developer of Nginx, currently the world's most popular web server, has quit the project, stating that he no longer sees it as "a free and open source project… for the public good."
Later that year, two of Nginx's leaders, Maxim Konovalov and Igor Sysoev, were detained and interrogated in their homes by armed Russian state agents.
While the criminal charges and rights do not appear to have materialized, the implications of a Russian company's intrusion into a popular open source piece of the web's infrastructure caused some alarm.
Comments on Hacker News, including one by a purported employee of F5, suggest Dounin opposed the assigning of published CVEs (Common Vulnerabilities and Exposures) to bugs in aspects of QUIC.
MegaZone wrote to Ars (noting that he only spoke for himself and not F5), stating, "It's an unfortunate situation, but I think we did the right thing for the users in assigning CVEs and following public disclosure practices.
F5 is committed to delivering successful open source projects that require a large and diverse community of contributors, as well as applying rigorous industry standards forassigning and scoring identified vulnerabilities.
The original article contains 833 words, the summary contains 188 words. Saved 77%. I'm a bot and I'm open source!
all 17 comments