haskell / haskell/security-advisories
How should OSV.dev consumers of Haskell Security Advisory DB records provide feedback on them?
- Dominant language
- Haskell
- Stars
- 64
- Forks
- 27
- Avg merge
- 3h 39m
- Merged PRs (30d)
- 1
Description
We're seeking to shorten the feedback loop by directly connecting OSV.dev downstream consumers of Haskell vulnerabilities with the Haskell Security Advisory DB for any corrective feedback on individual records.
Could you clearly define a feedback channel (file an issue, create a PR) for downstream users to follow to be able to correct a problem with an OSV record published in the Haskell Security Advisory DB?
See https://github.com/google/osv.dev/issues/2191 for more context.
Contributor guide
Research direction
Start by reviewing the repository's existing contribution guidance and the context in google/osv.dev issue 2191. Document whether downstream users should file an issue or create a pull request for correcting an individual advisory record, and make the chosen feedback path clear to OSV.dev consumers.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- haskell
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100