Description
As of today, only security advisories created explicitly/directly by a repo admin [1] are shown in the advisories tab. You do not get to include 'official' CVEs that have been ingested from the wider CVE ecosystem. This requires copy-paste duplication.
I would like to suggest the following:
-
Allow inclusion of official CVEs by repo admins using existing data.
-
Instead of requiring copy-paste, as today, provide a pathway to include/transclude the CVE into the advisories tab. For example, a drop-down with "Include in Security Advisories".
-
It would be good to distinguish visually between official CVEs and GH security advisories. Not sure if a separate list is appropriate or just tags. Worth experimenting.
-
Should the CVEs appear automatically on the page without repo admin intervention? Or should it require action/approval? Configurable? Likely requires a bit of thought about risk management.
More broadly, I think the Security Advisory page could act as a 'hub' for security-related topics that consumers should be aware of.
[1] Not sure what the correct role name is here, so s/repo admin/other/
to whatever is appropriate :-).
/cc @ronwoch