Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RustSec advisory Omission on potentially actionable fix(es) #684

Closed
pinkforest opened this issue Sep 17, 2022 · 3 comments
Closed

RustSec advisory Omission on potentially actionable fix(es) #684

pinkforest opened this issue Sep 17, 2022 · 3 comments

Comments

@pinkforest
Copy link

pinkforest commented Sep 17, 2022

Follow-Up from: #683 as another issue

We typically strive hard to include actionable advice as to any fixes if any on informational advisories.

Currently GHSA Is omitting to include that actionable advice we've included -

This means when Dependabot raises issue with the repo maintainer they don't really know how to resolve it.

e.g. ansi_term we provided advice as to how to fix it: https://rustsec.org/advisories/RUSTSEC-2021-0139.html

But GHSA omitted this: GHSA-74w3-p89x-ffgh

Problem with omitting this information is that people tend to ignore advisories that have no actionable fixes.

Perhaps even saying in GHSA that the RustSec advisory referenced may contain actionable fixes as to how to resolve the advisory can help the advisory consumer.

@darakian
Copy link
Contributor

darakian commented Apr 5, 2023

Hey @pinkforest is this issue roughly the same as #683 and can we close it out if so?

@pinkforest
Copy link
Author

Separate issue and we talked about it extensively :) But I'll close it since I trust this has been raised elsewhere.

@pinkforest pinkforest closed this as not planned Won't fix, can't repro, duplicate, stale Apr 6, 2023
@darakian
Copy link
Contributor

darakian commented Apr 6, 2023

Right on :)
Wanted to double check before just closing the issue out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants