Skip to content

Request a CVE for GHSA-rggj-c47j-46v9 #592

Description

@indigo423

GHSA-rggj-c47j-46v9 is published and its patched_versions is set to 0.8.0, so the disclosure itself is complete. No CVE has been requested: the advisory still reports cve: none.

GitHub can assign one as a CNA from the advisory page ("Request CVE"), which makes the issue citable outside GitHub and picks it up in downstream vulnerability databases and SCA tooling.

Worth deciding rather than leaving implicit. Either request it, or note on the advisory that a CVE is deliberately not being sought.

Filed while archiving the bound-flow-session-state change, whose task 7.3 covered coordinating this. That change lives under openspec/, which is gitignored, so the task would not have survived the archive.

Related: #480.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions