Skip to content

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Jan 14, 2026

Add gsm: advisory field in support of issue #305

  • Modified the schemas, specs, and README to add "gsm:" advisory field (similar to "ghsa:" field).
  • Add GSM-2016-16 advisory

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What happens when this GSM advisory eventually get's assigned a CVE or added to GitHub Security Advisories DB? Will we end up with a GHSA- and CVE- file? Could the github_advisory_sync.rb automatically rename GSM-* to CVE-*/GHSA-*?

@jasnow
Copy link
Contributor Author

jasnow commented Jan 14, 2026

Good questions

What happens when this GSM advisory eventually get's assigned a CVE or added
to GitHub Security Advisories DB? Will we end up with a GHSA- and CVE- file?

I think that the PR#585 lint check's purpose is to flag duplicate advisories.

Could the github_advisory_sync.rb automatically rename GSM-* to CVE-/GHSA-?

We could watch for it and add a feature when it happens.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants