Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

doc: add duplicate CVE check in sec. release doc #39845

Closed
wants to merge 1 commit into from

Commits on Aug 23, 2021

  1. doc: add duplicate CVE check in sec. release doc

    This commit adds a note about only creating a CVE for Node.js
    vulnerabilities.
    
    The motivation for this is a recent HackerOne report where I created a
    CVE for a c-ares issue. This CVE should have been created by the c-ares
    project, and it was later, but we never updated our HackerOne report to
    use their CVE number. Hopefully this extra note in the release doc will
    help us check for this situaion and avoid this in the future.
    
    Refs: https://hackerone.com/reports/1178337
    danbev committed Aug 23, 2021
    Configuration menu
    Copy the full SHA
    8017db8 View commit details
    Browse the repository at this point in the history