Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What offends me is a "security scanner" for "ground truth" using fake checksums to verify integrity of its dependencies ;-)

https://github.com/TheAuditorTool/Auditor/commit/f77173a5517...



Yeh, i dont dont use nix so when asked to follow the link? It didnt work as it should. And because i dont use nix? Hard to catch it until my friend did...

That said? Did you the hash fail? Yes it did, security working as intended... Anything more to add? :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: