Re: Free Software security vulnerabilities: Heartbleed and other case studies?

2017-08-21 Thread Hugo Roy
Thanks Vitaly! It's true that many license compliance tools are now taking security into account, which is an interesting development. Also on topic: https://www.esmt.org/sites/default/files/dsi_ipr5_engl-dt.pdf Best, Hugo ↪ Vitaly Repin / août 14, 2017 12:11: Hello, I think I have to add my

Re: Free Software security vulnerabilities: Heartbleed and other case studies?

2017-08-14 Thread Vitaly Repin
Hello, I think I have to add my 5 cents. There are commercial (ironically proprietary) products on the market which analyze the software and build a list of open source dependencies. Then, based on this list of open source dependencies, they build a list of vulnerabilities which might be

Re: Free Software security vulnerabilities: Heartbleed and other case studies?

2017-07-26 Thread Bastien Guerry
Hi Hugo, Hugo Roy writes: > Any case studies on how the world dealt to react quickly and update > systems in reponse to Heartbleed for instance? I remember blackduck had some reports comparing FLOSS/non-FLOSS with respect to their security, I found this, but I’m sure there are