Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Where else should be we publish or notify about advisories? #161

Open
frasertweedale opened this issue Mar 12, 2024 · 4 comments
Open

Where else should be we publish or notify about advisories? #161

frasertweedale opened this issue Mar 12, 2024 · 4 comments

Comments

@frasertweedale
Copy link
Collaborator

Summary

We have the site, (soon) an atom feed, and osv.dev with whatever downstream notification capabilities it has.

But we received a question about whether we publish in discourse, newletters, etc.

Let's discuss at the next SRT meeting and make a plan. It may involve community engagement to decide what will have the biggest impact.

@frasertweedale frasertweedale mentioned this issue Mar 12, 2024
3 tasks
@hasufell
Copy link
Member

I think Haskell weekly newsletter is appropriate, at least for high impact vulnerabilities.

Discourse may be a bit off, because it's quite specific and doesn't really warrant a discussion (most of the time).

@ysangkok
Copy link
Member

ysangkok commented Jan 2, 2025

I have added OSV support to Renovate now, you can see hackage listed in the configuration. However, the OSV functionality in Renovate is off by default. If turned on, people get notified about advisories relevant to them.

@blackheaven
Copy link
Collaborator

@ysangkok That's great, thanks for your hard work!

@frasertweedale
Copy link
Collaborator Author

@ysangkok thank you very much! I will mention this progress in the SRT Q4 report.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants