Skip to content

Add GMS-2020-1.yml to acorn

Sven Strickroth requested to merge (removed):GMS-2020-1 into master

There should be documentation on how to file unaffected versions, especially when backports of fixes are published.

To be checked:

  • identifier should be the CVE id when it exists.
  • title is a short description. It does not contain the package name.
  • description must not contain an overview of the package, fixed versions, affected versions, solution or links. It leverages the Markdown syntax.
  • date is the date on which the advisory was made public.
  • not_impacted lists old versions that are not impacted, if any, the fixed versions.
  • solution tells how to remediate the vulnerability.
  • urls must contain URLs specific to the vulnerability, not URLs generic to the package itself.

Merge request reports