3 ms·
For anything that already has a CVE, yes. You can add information about CVEs that are currently "unreviewed" by the GitHub curation team. By doing so, you'll bu
by greysteil 5y ago
For anything that already has a CVE, yes. You can add information about CVEs that are currently "unreviewed" by the GitHub curation team. By doing so, you'll bump those to the top of the stack for our curators to review (and help them review them). Once reviewed, they'll trigger Dependabot alerts, show up in npm audit, and be more usable by anyone else consuming the data.
For anything that doesn't already have a CVE, no. We don't want that disclosure process to happen in public - we recommend you reach out to the maintainer privately. (Currently we don't have an on-platform way to do that, but we're planning one.)
- alexchantavy 5y agoMight be a dumb question but is there a mapping from CVE to GHSA or vice versa? If so, then where is it listed/described? Edit: answered my own question - each GHSA in the repo has an `aliases` field and it seems that contains CVE; neat. Thanks for sharing!