gh-issues icon indicating copy to clipboard operation
gh-issues copied to clipboard

Provide downstream notification to forks of security issues/vulnerabilities when they become public

Open david-a-wheeler opened this issue 8 years ago • 2 comments

Please support downstream notification to forks of security issues/vulnerabilities when they are made public. This could perhaps be done via a specific vulnerability tag like “security”, but really any implementation would be fine.

david-a-wheeler avatar Jun 24 '16 00:06 david-a-wheeler

Great one. The new security advisories work may address this though I'm not sure that forks are informed. @jhutchings1 may know

jeffmcaffer avatar May 24 '19 21:05 jeffmcaffer

That's not functionality we support in the security advisories beta, but it's very good feedback for us to consider for later. Thanks!

jhutchings1 avatar May 31 '19 00:05 jhutchings1