Duplicate Advisory IDs in Security Advisories Wiki
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 3.2k
- Forks
- 692
- PR merge metrics
- No merged PRs in 30d
Description
Describe the bug
Recently, Security Advisories containing duplicate/reused PHSA IDs have been published.
A few examples:
- PHSA-2022-0444 (expat for 2.0) & PHSA-2022-0444 (mariadb for 3.0)
- PHSA-2022-0444 (vim, expat, go for 2.0) & PHSA-2022-0444 (gnutls, curl, go, python3 for 3.0)
- PHSA-2022-0443 (cassandra for 2.0) & PHSA-2022-0443 (ImageMagick for 3.0)
...
Reproduction steps
n/a
Expected behavior
It is expected for this ID to be unique, as having the same PHSA for different advisories is confusing.
Additional context
As a side note, this issue seems to have been introduced after addressing #1212. I questioned the change of the format Advisory ID as in the past it included the version, which resolves these conflicting ID issues.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by comparing the linked Security Update wiki pages and read the context from #1212, especially the change that removed the version from Advisory IDs. Determine how IDs are assigned across Photon versions and define a consistent uniqueness rule; done means the affected advisories no longer reuse an ID and the naming scheme is documented.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100