Hi Martin,
My colleague and I logged this call twice as we could not see Sid's original post, hence I created an account and logged a second post.
Your response below only answers our third query, we still require response on queries 1 and 2.
Our questions:
Can you confirm how the WinSCP application is updated?
- Is it community driven updates?
- Is there a security vetting process to ensure vulnerabilities/backdoors are not introduced?
- If a security related issue has been identified which is deemed a critical risk, what are the timescales (estimated) for resolving these type of issues? (Martin response: 'Critical issues are typically addressed within several days.')