Cory tells a tale of every open-source project's worse nightmare: a report of a serious security flaw in the software. Originally presented at DjangoCon EU 2015, Cardiff.
Panic
View Slide
Hi
Me@lukasaoz@lukasa
A Story
CVE 2015-2296A Story About Panic
Act 1: TheDistant Past(2014)
TO ACTION!
???
1. Contact Email
2. GPG Keys90DC AE40 FEA7 4B14 9B70 662D F25F 2144 EEC1 373D
Good Enough?
Act 2: TheDistant Now
Credit: Rachel Kramer https://www.flickr.com/photos/rkramer62/15877419359
3. Lots of Detail
Move TooFast
4. No Weekends
5. Get a CVE
6. WarnDownstream
7. IdentifyVersions
8. Policy
docs.python-requests.org/en/latest/community/vulnerabilities/
Thanks!✨✨