Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upSecurity Advisories: Traceability #92
Open
Labels
Projects
Comments
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Summary
Security Advisories Traceability allows users to see what source code and version includes the fix for the noted vulnerability.
Intended Outcome
Including information on the fixed version directly in the advisory will make it easier for users to determine if they have addressed a particular vulnerability, and if a patch is available.
How will it work?
Today, GitHub Security Advisories enable maintainers to privately discuss, fix, and disclose information about vulnerabilities in their projects. This information is used to automatically trigger security updates for participating GitHub repositories. At or after the publication of a Security Advisory, the creator will be able to add information about the patch or minimum version containing the fix.