|
|
Subscribe / Log in / New account

Resurrecting DWF

Resurrecting DWF

Posted Apr 8, 2021 13:54 UTC (Thu) by mjcox@redhat.com (guest, #31775)
In reply to: Resurrecting DWF by dsommers
Parent article: Resurrecting DWF

For CNAs the new automation is already proving very helpful in getting CVEs assigned and populated quickly. In my role at Apache, the Apache Security Team is a CNA, and we can use the automation API to get a new CVE name instantly. Then when we want to publish it we submit a PR to the CVE project github and the entry is public at mitre.org within an hour or two (even during holidays/weekends). Further automation coming in 2021 will let us use the API to do that publishing, removing the github PR step, and allowing us to allow various (trained) sub projects to do all those steps themselves.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds