Skip to content

Process to create new advisories? #288

Closed
@maitre-matt

Description

@maitre-matt

I am looking into adding entries for the malicious PyPI packages reported here:

Would you have more details about what "Make your change to the advisory file" entails in CONTRIBUTING.md?

For instance:

  • Should I create files under advisories/unreviewed or advisories/github-reviewed? Are files moved from one folder to the other automatically?
  • How do I come up with the folder/file name (ex: GHSA-6346-5r4h-ff5x)?

Happy to send a PR on CONTRIBUTING.md to include the guidance received here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions