← Graph

Have you reported these issues upstream to Devise?

question 2 connections

Audience question about whether the speaker filed an issue with the Devise maintainers. Answer: he emailed about the pepper leak privately (not wanting to discuss it publicly first), got no reply after three months, and now feels justified talking about it publicly. Intends to contribute a fix eventually, but emphasizes that shipping API-breaking security changes in a library used by people who only bump packages is hard — OpenSSL still supports 25-year-old APIs for the same reason; a less painful migration path needs to be found.

answer_summary
He emailed Devise 3 months ago with no reply; plans a fix but notes breaking API changes in security libraries are costly for users who only update packages.
question Have you reported these issues upstream to Devise?
about
Devise tool
About the Devise maintainers' response to security reports.
question Have you reported these issues upstream to Devise?
asked_at
Asked during Q&A.

Provenance

Read by
1 extraction