Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If the feature is in the code that's downloaded, regardless of whether or not the build process enables it by default, the code is definitely being shipped.


BRB, filing CVE's against literally any project with example code in their documentation...


That's actually supported by the CVE program rules. Have at it if you find examples with security vulns.


I've actually seen CVEs like that before, I agree that's bonkers but I have seen it...


Given how frequently people copy and paste example code… why is that surprising? Folks need to be informed. CVEs are a channel for that.


Pssst: People who copy+paste example code aren't checking CVEs


Yes. It's no different from any optional feature. Actual beta features should only be shipped in beta software .




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: