jenkins.io
jenkins.io copied to clipboard
Adding details about CVEs in third party dependencies
As the reporting of CVEs is a recurrent topic within the security team, I would like to clarify our standpoint.
Quickly addressed the merge conflicts I introduced.
Hi @daniel-beck, I wanted to follow up and see if your concerns were addressed with the updates that have been made. If not, what could be changed to provide the right messaging?
I liked the phrasing of this enough to quote it in a community.jenkins.io post.
Pending a conversation with Wadeck we've been postponing repeatedly since January…
Please take a moment and address the merge conflicts of your pull request. Thanks!