Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE submitted via GitHub advisory targets wrong package #5064

Open
taiki-e opened this issue Dec 9, 2024 · 0 comments
Open

CVE submitted via GitHub advisory targets wrong package #5064

taiki-e opened this issue Dec 9, 2024 · 0 comments

Comments

@taiki-e
Copy link

taiki-e commented Dec 9, 2024

I have written three advisories in crossbeam-rs/crossbeam and obtained CVE via GitHub advisory for all of them.

Each of these advisories is for a different package in the same repository.

However, according to the CVE submitted by GitHub, it appears that these are all treated as crossbeam package issues, which causes issues to be reported in the wrong packages or not reported in packages that should be reported (crossbeam-rs/crossbeam#1151).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant