> an interesting target for attacks
Jenkins security is a joke. You can find security issues without trying, even in core. And the process to resolve them seems to be really broken.
Have you helped to improve this situation by actually reporting them via the proper channels?
https://wiki.jenkins-ci.org/display/JENKINS/Security+Advisories
/James
--
You received this message because you are subscribed to a topic in the Google Groups "Jenkins Users" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/jenkinsci-users/3O8vpxrWZH8/unsubscribe.
To unsubscribe from this group and all its topics, send an email to jenkinsci-use...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.
> Of course, you'd need a secure way to make sure it's actually his signature, but that should be easier than changing the entire distribution chain.That's exactly the problem. Any ideas on how I can do that?Thanks,
Abhijith
--
--
You received this message because you are subscribed to the Google Groups "Jenkins Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-use...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.
--
You received this message because you are subscribed to the Google Groups "Jenkins Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-use...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.