Nmap Development mailing list archives

NPCAP GitHub Security Advisories


From: "Sethi, Jay" <jsethi () hydro mb ca>
Date: Thu, 22 Apr 2021 17:17:53 +0000

Hello nmap dev team!

I work for Manitoba Hydro, a utility in Manitoba Candada. We use nmap (and NPCAP!). As part of NERC CIP compliance, we 
are required to check regularly for security advisories. I recently noticed the following on the GitHub page:
The npcap change log notes a few releases that resolve CVEs
npcap/CHANGELOG.md at master * nmap/npcap * GitHub<https://github.com/nmap/npcap/blob/master/CHANGELOG.md>
(For example, Npcap 0.9984 [2019-10-30])

However the GitHub page has a tab for security advisories that does not list any advisories:
Security Advisories * nmap/npcap * GitHub<https://github.com/nmap/npcap/security/advisories>

Is it the case that there are actually no security advisories for npcap, and that the "CVE" that were resolved were 
security enhancements? Or is it just GitHub that has an extra page for advisories that's not really going to be used?

Thank-you for taking the time to answer my question and for building excellent security scanning software!

Jay Sethi
Manitoba Hydro

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/

Current thread: