Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Requires a GitHub security advisory and

> Only advisories reviewed by GitHub trigger alerts.

From https://docs.github.com/en/code-security/concepts/supply-cha...



So it forces everyone to use more GitHub stuff?

Maybe I'm misunderstanding, but this means I now need to submit to GitHub Security Advisor to get my security fix out ASAP?


Nothing changed here and it seems reasonable to me.

If you want GitHub to tell people about your security fix, someone needs to tell GitHub about the fix first.

AFAIK they mostly pull from the normal sources like NVD automatically, but you can also submit to GitHub directly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: