Hacker News new | past | comments | ask | show | jobs | submit login
Ask HN: How much do you care about CVE in your team?
4 points by megamix 4 days ago | hide | past | favorite | 5 comments
How much do you utilise vulnerability scanning tools at your job and how much does your team care about fixing them?

Do you handle internal applications differently?

Edit/update: Please mention your industry/sector as well.






We do have tools in every step of the sdlc so we can find issues as early as possible. Anything that is exploitable and left unmatched is a compliance violation so we take it very seriously. That said, exploitability is very (expensive) hard to proof, so in practice we try to mitigate via upgrading instead of long pointless discussions about risk. The second thing this forces us, is to look at complexity and tech-debt in a new light.

And in what industry/sector (possibly markets) are you mainly operating in ?

Yes get chased up about it by security teams. Internal or external apps.

It's mandatory as part of the SDLC and support by appropriate tooling, unfixed higher level vulnerabilities are periodically tracked by middle-upper management

Tools in the pipelines detect and report on CVEs found.

We block high/critical by default and the rest are given a deadline to be resolved in agreement with security.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: