|
I'm trying to determine how to best create and assign advisories for a new ecosystem advisory database that will import many old upstream advisories with the appropriate versions and identifiers for our ecosystem's packages that directly shipped the vulnerable upstream. It seems the existing open source ecosystems do a mix of things here:
I'm leaning towards the latter behavior but was curious if this project had a view on the best practice as a downstream consumer of many such databases. |
Answered by
jess-lowe
Sep 17, 2025
Replies: 1 comment
|
We would also lean towards the latter behaviour for traceability purposes. |
0 replies
Answer selected by
mbauman
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
We would also lean towards the latter behaviour for traceability purposes.