On Wed, Aug 24, 2022, at 11:56, Kevin Kofler via devel wrote: > That was exactly my point though. If nobody finds CVEs, then nobody has to > fix them. We can only fix what we know about, and blackhats can only attack > what they know about. The fact that there are no new CVEs (and therefore fixes) does not imply that there are no security vulnerabilities (potentially) exploited in the wild. -- Fabio Alessandro "Fale" Locati fale.io _______________________________________________ devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue