• ignirtoq@feddit.online
    link
    fedilink
    English
    arrow-up
    23
    arrow-down
    1
    ·
    6 hours ago

    The problem is that some small but non-zero fraction of these bugs may be exploitable security flaws with the software, and these bug reports are on the open internet. So if they just ignore them all, they risk overlooking a genuine vulnerability that a bad actor can then more easily find and use. Then the FOSS project gets the blame, because the bug report was there, they should have fixed it!