Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

https://github.blog/security/supply-chain-security/inside-th... goes into it more

As mentioned by another commenter, they intentionally have a human reviewer in the process before a GitHub Security Advisory (GHSA) becomes "official" post-publish

(this is separate to getting CVE ID assigned, if wanted)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: