[PATCH v2] Move CVE information into advisories directory

Florian Weimer fweimer@redhat.com
Thu Dec 7 16:49:34 GMT 2023


* Siddhesh Poyarekar:

>> So the version number would really be a comment that you should
>> ignore
>> when consuming this data.  It can also handle the case of multiple
>> fixing commits and avoid unclarity about what exactly needs to be
>> backported.
>> Do you think it would be to onerous to gather the commit IDs?
>> Something
>> like this
>> git log --pretty=oneline --grep
>> ec6b95c3303c700eb89eebeda2d7264cc184a796 release/2.3{4..8}/master
>> seems to work reasonably well, though.
>
> That ought to work.  I'll add a little README as a separate commit
> with some advice on creating these advisories.  Do you mind if I add
> your Vulnerable-Backport+Fix-Backport suggestion and push this?  I
> want to file the CNA registration this week so that we have some hope
> of getting the CNA up (and announced in NEWS) for 2.39.

I suppose we could do post-commit review for this because it's not code?
So please go ahead if it's time-critical.

Thanks,
Florian



More information about the Libc-alpha mailing list