Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Investigate downstream advisory usage #1749

Open
amousset opened this issue Aug 19, 2023 · 0 comments
Open

Investigate downstream advisory usage #1749

amousset opened this issue Aug 19, 2023 · 0 comments

Comments

@amousset
Copy link
Member

As discussed in #1738 (comment), issuing an informational="notice" advisory would cause alerts similar to actual vulnerabilities in some cases, which is undesirable and prevents using this type of advisory in some cases.

Our informational advisories seem to map quite poorly in most vulnerability-handling contexts, and we may consider skipping some of them in the export for osv.dev

I started a broader review of of the vulnerability audit ecosystem consumes our advisories (and other Rust-related advisories too). The test repository with the current results is https://github.com/amousset/vulnerable_crate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant