vmware / vmware/photon

Duplicate Advisory IDs in Security Advisories Wiki

Open
#1,353 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
C
Stars
3.2k
Forks
692
PR merge metrics
No merged PRs in 30d

Description

Describe the bug

Recently, Security Advisories containing duplicate/reused PHSA IDs have been published.

A few examples:

...

Reproduction steps
n/a
Expected behavior

It is expected for this ID to be unique, as having the same PHSA for different advisories is confusing.

Additional context

As a side note, this issue seems to have been introduced after addressing #1212. I questioned the change of the format Advisory ID as in the past it included the version, which resolves these conflicting ID issues.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by comparing the linked Security Update wiki pages and read the context from #1212, especially the change that removed the version from Advisory IDs. Determine how IDs are assigned across Photon versions and define a consistent uniqueness rule; done means the affected advisories no longer reuse an ID and the naming scheme is documented.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.