6 ms·
> The default applies only to version updates. Security updates still open immediately, so critical fixes are never delayed. does this require a real vulnerabi
by bstsb 2mo ago
> The default applies only to version updates. Security updates still open immediately, so critical fixes are never delayed.
does this require a real vulnerability report, or CVE? if the package is compromised would they just be able to push a false "critical update" that bypasses this wait?
- sonukapoor 2mo ago[dead]
- MeetingsBrowser 2mo agoRequires a GitHub security advisory and > Only advisories reviewed by GitHub trigger alerts. From https://docs.github.com/en/code-security/concepts/supply-chain-security/dependabot-alerts https://docs.github.com/en/code-security/concepts/supply-cha...
- gizzlon 2mo agoSo it forces everyone to use more GitHub stuff? Maybe I'm misunderstanding, but this means I now need to submit to GitHub Security Advisor to get my security fix out ASAP?
- MeetingsBrowser 2mo agoNothing changed here and it seems reasonable to me. If you want GitHub to tell people about your security fix, someone needs to tell GitHub about the fix first. AFAIK they mostly pull from the normal sources like NVD automatically, but you can also submit to GitHub directly.
- doctorpangloss 2mo agoThe idiocy of cooldowns speaks for itself.
- fobcodes 2mo ago[dead]