haskell / haskell/security-advisories

How should OSV.dev consumers of Haskell Security Advisory DB records provide feedback on them?

Open
#252 7 comments 0 reactions 0 assignees View on GitHub
good first issue ZuriHac
Dominant language
Haskell
Stars
64
Forks
27
Avg merge
3h 39m
Merged PRs (30d)
1

Description

We're seeking to shorten the feedback loop by directly connecting OSV.dev downstream consumers of Haskell vulnerabilities with the Haskell Security Advisory DB for any corrective feedback on individual records.

Could you clearly define a feedback channel (file an issue, create a PR) for downstream users to follow to be able to correct a problem with an OSV record published in the Haskell Security Advisory DB?

See https://github.com/google/osv.dev/issues/2191 for more context.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the repository's existing contribution guidance and the context in google/osv.dev issue 2191. Document whether downstream users should file an issue or create a pull request for correcting an individual advisory record, and make the chosen feedback path clear to OSV.dev consumers.

Written by the indexing model from the issue text.

Assessment

Tech stack
haskell
Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.