Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.
Sign upIdea: Security advisories as part of crates.io metadata tools and infrastructure #406
Comments
This comment has been minimized.
This comment has been minimized.
|
Thanks for the report! I'd love to see a feature like this myself, but I think we'd probably want to go the RFC route as it's such a major feature. |
This comment has been minimized.
This comment has been minimized.
|
@alexcrichton I have the work-in-progress at https://github.com/untitaker/rfcs/blob/security-advisories/text/0000-security-advisories.md. The last three sections are not written yet, so I'll not file a PR yet.
|
This comment has been minimized.
This comment has been minimized.
|
I'll close this for now, let's continue discussion at Discourse. |
untitaker
closed this
Aug 24, 2016
This comment has been minimized.
This comment has been minimized.
|
Ok! |
This comment has been minimized.
This comment has been minimized.
|
@untitaker where are you discussing this? I'd like to help. I know I suggested |
This comment has been minimized.
This comment has been minimized.
|
The discourse forum, but I didn't do much since then. On 4 September 2016 00:46:34 CEST, Tony Arcieri notifications@github.com wrote:
Sent from my Android device with K-9 Mail. Please excuse my brevity. |
This comment has been minimized.
This comment has been minimized.
|
@untitaker have you thought about publishing this on the Discourse forum as a pre-RFC? https://github.com/untitaker/rfcs/blob/security-advisories/text/0000-security-advisories.md |
This comment has been minimized.
This comment has been minimized.
|
It is unfinished and most likely will need a rewrite given that I can't sense a lot of support for having a dedicated command for vulnerability disclosure. Also I'd rather centralize this discussion on Discourse. On 4 September 2016 01:17:49 CEST, Tony Arcieri notifications@github.com wrote:
Sent from my Android device with K-9 Mail. Please excuse my brevity. |
untitaker commentedAug 22, 2016
I originally started this discussion at internals.rust-lang.org and recieved generally positive feedback. I was told by @Bascule and several people in IRC to open an issue on this tracker. Here's a revised/summarized proposal (not exactly the same as the original one):
cargo vulnthat marks all existing versions as vulnerable (API on crates.io required for this) and maybe also guides the user through requesting a CVE