3 ms·
Requires a GitHub security advisory and > Only advisories reviewed by GitHub trigger alerts. From https://docs.github.com/en/code-security/concepts/supply-cha
by MeetingsBrowser 3mo ago
Requires a GitHub security advisory and
> Only advisories reviewed by GitHub trigger alerts.
From https://docs.github.com/en/code-security/concepts/supply-chain-security/dependabot-alerts https://docs.github.com/en/code-security/concepts/supply-cha...
- gizzlon 3mo agoSo it forces everyone to use more GitHub stuff? Maybe I'm misunderstanding, but this means I now need to submit to GitHub Security Advisor to get my security fix out ASAP?
- MeetingsBrowser 3mo agoNothing changed here and it seems reasonable to me. If you want GitHub to tell people about your security fix, someone needs to tell GitHub about the fix first. AFAIK they mostly pull from the normal sources like NVD automatically, but you can also submit to GitHub directly.