oss-sec mailing list archives

Re: Re: Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely


From: Greg KH <greg () kroah com>
Date: Thu, 27 Aug 2026 07:24:46 +0200

On Thu, Aug 27, 2026 at 01:03:47AM -0400, Syed wrote:
Yes,
https://www.google.com/url?q=http://cve.org&source=gmail&ust=1787893426670000&sa=E
json records are known to have this issue, because almost
all fields are not required.

Ah, I'm talking to a bot

{sigh}

Fair. Optional means a CNA leaving credits empty is behaving correctly,
not incorrectly, and the post should have said that plainly.

The squabbling you mention is the useful part, and it is in no spec.

The "squabbling" happens with people, and I think I'll stop responding
here as this isn't going to go very well for everyone involved...

greg k-h


Current thread: