Resurrecting DWF
Resurrecting DWF
Posted Apr 8, 2021 13:54 UTC (Thu) by mjcox@redhat.com (guest, #31775)In reply to: Resurrecting DWF by dsommers
Parent article: Resurrecting DWF
For CNAs the new automation is already proving very helpful in getting CVEs assigned and populated quickly. In my role at Apache, the Apache Security Team is a CNA, and we can use the automation API to get a new CVE name instantly. Then when we want to publish it we submit a PR to the CVE project github and the entry is public at mitre.org within an hour or two (even during holidays/weekends). Further automation coming in 2021 will let us use the API to do that publishing, removing the github PR step, and allowing us to allow various (trained) sub projects to do all those steps themselves.
