-
I'm trying to determine how to best create and assign advisories for a new ecosystem advisory database that will import many old upstream advisories with the appropriate versions and identifiers for our ecosystem's packages that directly shipped the vulnerable upstream. It seems the existing open source ecosystems do a mix of things here:
I'm leaning towards the latter behavior but was curious if this project had a view on the best practice as a downstream consumer of many such databases. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
We would also lean towards the latter behaviour for traceability purposes. |
Beta Was this translation helpful? Give feedback.
We would also lean towards the latter behaviour for traceability purposes.