How thorough is this testing and review process? Am I understanding this correctly that they only review portions of the code, on top of function & security testing?
anton @ anton @lemmy.blahaj.zone Posts 0Comments 404Joined 2 yr. ago
anton @ anton @lemmy.blahaj.zone
Posts
0
Comments
404
Joined
2 yr. ago
This is how I read it:
They did a review of some of the tests, but ran all.
The source code was reviewed in its entirety.
They found vulnerabilities, but because "[...] these potential vulnerabilities would be exploitable only by a vendor insider attack.
No open issues remain for this area of review."
Problems and discrepancies they found are in an attachment to another report and in jira, both of which are confidential.