jenkins.io
jenkins.io copied to clipboard
CNA scope conflict improvement
We recently had a misunderstanding regarding the assignment of CVEs when there's a scope conflict with another CNA. (see SECURITY-3141)
Disagree. We still handled it by coordinating with the other CNA, we just didn't assign it ourselves. This exists because we need maintainers not to go run off themselves and have CVEs assigned.