[Secure-testing-team] inject-embedded-code-copies

Michael S. Gilbert michael.s.gilbert at gmail.com
Wed Aug 26 19:18:10 UTC 2009


On Wed, 26 Aug 2009 14:06:24 -0500, Raphael Geissert wrote:
> Michael S. Gilbert wrote:
> [...]
> > 
> > btw, my script is already smart enough to exclude fixed embeds; it uses
> > the <unfixed>/<removed>/<unknown>/<itp> tags in embedded-code-copies to
> > determine if an issue is open or not.  so as long as the data in
> > embedded-code-copies is accurate, then my script already only generates
> > TODOs for real issues.  hence, when i am done with this triage, you can
> > expect a lot of new <unfixed> entries (probably close to 200).
> > 
> 
> Does it also use the version information to determine what releases are
> affected?
> That's an important consideration IMO.

no it does not use version information at this time, and i agree that
that is definitely important.  i will spend the time on that when i
have a chance.

mike



More information about the Secure-testing-team mailing list