Përkrahësi i libxml2 ka hequr dorë nga një qasje e veçantë për eliminimin e dobësive

Nick Wellnhofer, the maintainer of the libxml2 library, announced that he will now treat vulnerabilities as regular bugs. Reports of vulnerabilities will not be prioritized and will be addressed as time allows. Information about the nature of the vulnerability will be made publicly available immediately, without waiting for a patch to be developed and distributed in distributions and operating systems. Nick has also stepped down as the maintainer of the libxslt library and expressed doubts that anyone would be willing to take on its support.

A note has been added to the project description of libxml2 stating that the library is written by enthusiasts, maintained by a single volunteer, is poorly tested, written in a memory-unsafe language, contains numerous vulnerabilities, and is not recommended for processing untrusted data. Security issue reports are recommended to be sent through the official public bug tracking system and will be processed like any other bugs. Vulnerabilities will no longer be hidden behind closed doors, and all existing information about security issues will be published immediately in the public domain, regardless of non-disclosure requirements until a specified date and without delaying the disclosure until the release.

It is expected that treating vulnerabilities as regular bugs will allow Nick to focus on his core work on libxml2 without being distracted by ad hoc tasks. Currently, Nick has to spend several hours a week handling vulnerability reports and preparing patches, which creates a significant burden considering that maintenance is carried out out of sheer enthusiasm.

It is noted that concealing information about vulnerabilities until updates are published and metrics like OpenSSF Scorecard is merely an attempt by large companies to induce a sense of guilt in maintainers and compel them to work for free. Imposing additional requirements on volunteer maintainers, who work without compensation, has been labeled a harmful practice.

Sipas Nikit, biblioteka libxml2 nuk ka nivelin e cilësisë të mjaftueshme për t'u përdorur në shfletues dhe sisteme operative. Megjithatë, kompani të mëdha si Apple, Google dhe Microsoft kanë filluar ta përdorin libxml2 në sistemet e tyre operative dhe produktet. Këto veprime janë quajtur të papërgjegjshme, dhe puna që po kryhet është përpjekje për të hequr simptomat, jo për të zgjidhur shkakun e problemeve. Sipas Nikit, do të ishte më mirë për projektin nëse kompanitë e përmendura do të ndalonin përdorimin e libxml2.

Burimi: opennet.ru

Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS đŸ”„ Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS | ProHoster