TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

"90% of Java services have critical or security vulnerabilities"

12 点作者 mihau大约 1 年前

3 条评论

mtmail大约 1 年前
I'd argue the "... or about the quirks of security reporting" part of the headline is more relevant. The author argues the 90% number is unrealistic and the statement shouldn't be trusted.
ArturSkowronski大约 1 年前
FYI: The full title is: "90% of Java services have critical or severe security vulnerabilities"... or about the quirks of security reporting
zer0faith大约 1 年前
Sorry I didn&#x27;t have the patience to fully read this click bait. If you use 3rd party packages (aka FOSS, Open Source, whatever they call it) those vulnerabilities are a by product of using the 3rd party package, it is the cost of doing business. They make SCA tools, even free ones to identify these issues. IMO, importing, updating, and using 3rd party packages in your development process are a part of technical debt and cyber hygiene, nothing more nothing less.<p>TL;DR Don&#x27;t be dumb, update your packages and don&#x27;t use vulnerable ones.