public inbox for libc-alpha@sourceware.org
 help / color / mirror / Atom feed
* [RFC] Publishing glibc advisories
@ 2023-10-12 21:50 Siddhesh Poyarekar
  2023-10-12 22:09 ` Noah Goldstein
                   ` (2 more replies)
  0 siblings, 3 replies; 11+ messages in thread
From: Siddhesh Poyarekar @ 2023-10-12 21:50 UTC (permalink / raw)
  To: GNU C Library; +Cc: Carlos O'Donell, Adhemerval Zanella

Hello folks,

I'm working on a way to publish glibc advisories and my first thought 
was to host all advisories in the repository in a `advisories` toplevel 
directory, but there's a bunch of information that is typically shared, 
that will be cumbersome to maintain within the repository.

As a result, I am thinking of requesting a separate repository, e.g. 
glibc-advisories.git to host the advisory files along with scripts to 
process them.  I'm thinking of using the OSV[1] format for the advisory 
files since that appears to be the growing standard for maintaining and 
sharing CVE information.

For formal announcements of CVEs (typically when they're fixed) I was 
thinking of sending out notifications to the openwall oss-security 
mailing list[2] since again, that seems to be where a bunch of FOSS 
projects that do their own security announcements send their notifications.

Any thoughts or comments on this?

Thanks,
Sid

[1] https://ossf.github.io/osv-schema/
[2] https://www.openwall.com/lists/oss-security/

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2023-11-07 15:11 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-10-12 21:50 [RFC] Publishing glibc advisories Siddhesh Poyarekar
2023-10-12 22:09 ` Noah Goldstein
2023-10-12 22:24   ` Siddhesh Poyarekar
2023-10-12 22:59     ` Noah Goldstein
2023-10-13  0:43       ` Siddhesh Poyarekar
2023-10-12 23:26 ` DJ Delorie
2023-10-13  0:43   ` Siddhesh Poyarekar
2023-10-13  1:51     ` Frank Ch. Eigler
2023-10-13  7:40 ` Florian Weimer
2023-10-13 10:50   ` Siddhesh Poyarekar
2023-11-07 15:03     ` Florian Weimer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).