[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: suggestion for checking unicode characters against "trojan source attacks"





Le mar. 9 nov. 2021 à 20:55, Felix Lechner <felix.lechner@lease-up.com> a écrit :
Hi Jérémy,

On Tue, Nov 9, 2021 at 11:48 AM Jérémy Lal <kapouer@melix.org> wrote:
>
> Ok, but the potential targets are source code files, like *.c *.cpp, *.js, *.py, *.rb etc...

It was only a stopgap measure. We held a release due to the large
number of false positives.

Please just let me know what you would like to see, and I will change
it again. Have you heard from the security team?

No, but as far as i can understand this CVE is difficult to evaluate,
It's a potential threat against source code... that's about it...

Reply to: