Hacker News new | ask | show | jobs
by bstsb 14 days ago
> The default applies only to version updates. Security updates still open immediately, so critical fixes are never delayed.

does this require a real vulnerability report, or CVE? if the package is compromised would they just be able to push a false "critical update" that bypasses this wait?

2 comments

Requires a GitHub security advisory and

> Only advisories reviewed by GitHub trigger alerts.

From https://docs.github.com/en/code-security/concepts/supply-cha...

So it forces everyone to use more GitHub stuff?

Maybe I'm misunderstanding, but this means I now need to submit to GitHub Security Advisor to get my security fix out ASAP?

Nothing changed here and it seems reasonable to me.

If you want GitHub to tell people about your security fix, someone needs to tell GitHub about the fix first.

AFAIK they mostly pull from the normal sources like NVD automatically, but you can also submit to GitHub directly.

The idiocy of cooldowns speaks for itself.