[PATCH v2] Move CVE information into advisories directory
Florian Weimer
fweimer@redhat.com
Thu Dec 7 16:49:34 GMT 2023
* Siddhesh Poyarekar:
>> So the version number would really be a comment that you should
>> ignore
>> when consuming this data. It can also handle the case of multiple
>> fixing commits and avoid unclarity about what exactly needs to be
>> backported.
>> Do you think it would be to onerous to gather the commit IDs?
>> Something
>> like this
>> git log --pretty=oneline --grep
>> ec6b95c3303c700eb89eebeda2d7264cc184a796 release/2.3{4..8}/master
>> seems to work reasonably well, though.
>
> That ought to work. I'll add a little README as a separate commit
> with some advice on creating these advisories. Do you mind if I add
> your Vulnerable-Backport+Fix-Backport suggestion and push this? I
> want to file the CNA registration this week so that we have some hope
> of getting the CNA up (and announced in NEWS) for 2.39.
I suppose we could do post-commit review for this because it's not code?
So please go ahead if it's time-critical.
Thanks,
Florian
More information about the Libc-alpha
mailing list