Skip to content

[Feature Request] Allow official CVEs to be shown on Security Advisory page #1564

Open
@msavy

Description

@msavy

As of today, only security advisories created explicitly/directly by a repo admin [1] are shown in the advisories tab. You do not get to include 'official' CVEs that have been ingested from the wider CVE ecosystem. This requires copy-paste duplication.

I would like to suggest the following:

  • Allow inclusion of official CVEs by repo admins using existing data.

  • Instead of requiring copy-paste, as today, provide a pathway to include/transclude the CVE into the advisories tab. For example, a drop-down with "Include in Security Advisories".

  • It would be good to distinguish visually between official CVEs and GH security advisories. Not sure if a separate list is appropriate or just tags. Worth experimenting.

  • Should the CVEs appear automatically on the page without repo admin intervention? Or should it require action/approval? Configurable? Likely requires a bit of thought about risk management.

More broadly, I think the Security Advisory page could act as a 'hub' for security-related topics that consumers should be aware of.

[1] Not sure what the correct role name is here, so s/repo admin/other/ to whatever is appropriate :-).

/cc @ronwoch

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions