Skip to content
Discussion options

You must be logged in to vote

So this is a situation where we do not have a great answer...

the current "best practice" is to file a distinct advisory/GHSA for each ecosystem. Each advisory should have the same CVE ID.
We will curate the ones with ecosystems we are able to broadcast and do so.

One example of this is CVE-2019-8331 on bootstrap which you can see has a few GHSA IDs, one for each ecosystem.

We do have an initiative in progress to allow us to broadcast one GHSA with many ecosystems. Once that is done the best practice will to simply file on GHSA with all the ecosystem/packages and it will be broadcast as one advisory.

Is this the info you need @JLLeitschuh ?

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@JLLeitschuh
Comment options

@rschultheis
Comment options

Answer selected by xcorail
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants