The House passed a defense spending bill saying you can't sell software to the DoD that has *any* known CVEs in it. congress.gov/bill/117th-con…
Post
Post
I can't see this policy being abused at all 🙄
Replying to @gsuberland
intent: security will be ensured reality: hackers (including those under the employ of foreign governments) can now perpetually tie up sales deals to the DoD by finding a bunch of bugs in a system and timing their disclosures so there's always at least one open CVE.



