Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If it helps, in the Renovate project we don't usually request a full CVE ID, but use the GitHub Security Advisory (GHSA) ID

You can use those numbers in changelogs as soon as they're published

There is some human review, which takes time, before the GHSA is "GitHub-reviewed" which then allows security scanners to pick it up

Then, the CVE ID can be assigned to it after-the-fact if need be, but the GHSA should be a sufficient starting point



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: