Re: How NOT to test OSS security

2021-04-21 Thread Craig Russell
I'd say that the time is long past when we should expect such bogus patches to appear in our most popular projects. Some of these bogus patches might be very tricky and appear to be valid. Let's all watch out. Craig > On Apr 21, 2021, at 8:16 AM, Shane Curcuru wrote: > > For those who

How NOT to test OSS security

2021-04-21 Thread Shane Curcuru
For those who review new contributions in their projects, a reminder: there are rare cases where new contributors might be submitting junk: https://fosspost.org/researchers-secretly-tried-to-add-vulnerabilities-to-linux-kernel/ Researchers from University of Minnesota wrote a paper about