GHSA SYNC: 1 new advisory; 2 modified advisories#990
GHSA SYNC: 1 new advisory; 2 modified advisories#990postmodern merged 3 commits intorubysec:masterfrom
Conversation
postmodern
left a comment
There was a problem hiding this comment.
If we want to indicate that a CVE is related to another CVE, related: cve: is already supported.
related:
cve:
- CVE-....
url:
- ...
postmodern
left a comment
There was a problem hiding this comment.
Should rubies/jruby/CVE-2011-4838.yml and rubies/ruby/CVE-2011-4815.yml also get related: cve: like the rubies/jruby/CVE-2019-16254.yml file? I am OK with merging this in it's current state.
My vote is keep them because it keeps the information separate. |
Agreed. Let us use |
GHSA SYNC: 1 new advisory; 2 modified advisories