How do you track security vulnerabilities?

unhinge@programming.dev to Linux@lemmy.ml – 75 points –

Do you rely on mailing lists or news articles for security vulnerabilities? Please share.

I only got to know about xz/liblzma ^[1] and curl ^[2] ^[3] vulnerabilities through lemmy (maybe because of high severity?).

34

You are viewing a single comment

Then, what does a package maintainer rely on?

Edit: I'm so dumb. It's obvious they'd check original developer's repo or issue tracker. I'm sorry

I don't know... I guess in mailing lists and pages like RSS feed from main enterprises like SuSE, Red Hat and Canonical