dotnet / dotnet/core

Security alerts on the announcements repo

Open
#7,954 2 comments 1 reaction 0 assignees View on GitHub
question
Dominant language
PowerShell
Stars
22k
Forks
4.9k
Avg merge
5d 5h
Merged PRs (30d)
29

Description

Watching issues in [the dotnet/announcements repo](https://github.com/dotnet/announcements) is a good way to get notified about security problems in .Net. The problem is that when you go to watch that repo, you also have the option to watch "Security alerts":

![](https://user-images.githubusercontent.com/287848/201049864-c87a72f3-d0fc-40c2-9a8e-445c7355c617.png)

This might sound like exactly what you want to do, but AFAICT, that would only provide notifications about security alerts under the Security tab, [which is empty in the announcements repo](https://github.com/dotnet/announcements/security/advisories).

That is quite a confusing situation to be in, is there something that can be done to improve it? I'm assuming that security alerts can't be disabled, but would it be proper to copy information about security issues to the Security tab? Or is the best option to note this in the README?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.