Skip to content

[GHSA-86rg-pf4c-5grg] add credit for CVE-2023-6944#6229

Merged
advisory-database[bot] merged 1 commit intogithub:pfeifferj/advisory-improvement-6229from
pfeifferj:chore/add-cve-2023-6944-credit
Oct 1, 2025
Merged

[GHSA-86rg-pf4c-5grg] add credit for CVE-2023-6944#6229
advisory-database[bot] merged 1 commit intogithub:pfeifferj/advisory-improvement-6229from
pfeifferj:chore/add-cve-2023-6944-credit

Conversation

@pfeifferj
Copy link

Inline with Open Source Vulnerability format and as supported in version 1.4.0 - adding credits field per original disclosure report and references provided in this CVE

@github-actions github-actions bot changed the base branch from main to pfeifferj/advisory-improvement-6229 September 30, 2025 08:39
@pfeifferj pfeifferj changed the title chore: add credit for CVE-2023-6944 [GHSA-86rg-pf4c-5grg] add credit for CVE-2023-6944 Sep 30, 2025
@shelbyc
Copy link
Contributor

shelbyc commented Oct 1, 2025

Hi @pfeifferj, the only credit that I can add to an advisory that's not based on a repository advisory is analyst credit. We can't add the finder label to global advisories; only code owners publishing repo GitHub Security Advisories can add the finder label to their repo advisory, which is then reflected in the corresponding global advisory. Are you OK with having credit linked in the advisory alongside the analyst label?

@pfeifferj
Copy link
Author

hi @shelbyc

I understand the situation. yes, I'm ok with having credit linked in the advisory alongside the analyst label. that would be appreciated!

just to confirm - you'll add the credit with the analyst label to the advisory? I didn't see such a label anywhere else in the repo

@advisory-database advisory-database bot merged commit 934ad4d into github:pfeifferj/advisory-improvement-6229 Oct 1, 2025
2 checks passed
@advisory-database
Copy link
Contributor

Hi @pfeifferj! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@shelbyc
Copy link
Contributor

shelbyc commented Oct 1, 2025

Hi @pfeifferj, you should be able to see a credit on the advisory with the Analyst label next to your GitHub handle. I also added https://www.cve.org/CVERecord?id=CVE-2023-6944 to the list of reference links so that people can find the original CVE record with your full name listed as reporter in the CVE credit section.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants