|
Message-ID: <225a8553-b59c-47ca-8483-a66b4c3b9ebb@notcve.org> Date: Fri, 10 Nov 2023 12:15:43 +0100 From: !CVE Team <contact@...cve.org> To: Solar Designer <solar@...nwall.com>, oss-security@...ts.openwall.com Subject: Re: !CVE: A new platform to track security issues not acknowledged by vendors Hello all, Thank you for your valuable feedback! We are always open to hear from the community and happy to improve for the benefit of all of us. We agree with Alexander on the exclamation mark issue, it can be tedious when searching in the mailing lists and other sites. Also with David that when possible it would be good to clearly distinct names even when it's not legally required. For those reasons, the !CVE team agreed to make the identifier more distinctive. The IDs are now NotCVE-YYYY-XXX and they are completely aligned to the notcve website name. So if someone is searching for NotCVE in the mailing list, Google, etc, will find what they are looking for. Those updates are already applied and because some sites have included the https://notcve.org/view.php?id=!CVE-2023-0001 link (@notCVE at X, etc.) we are automatically redirecting only that URL to the new one https://notcve.org/view.php?id=NotCVE-2023-0001 Thank you all again for your feedback! Kind regards, !CVE Team On 09/11/2023 00:13, Solar Designer wrote: > Hi, > > I don't like to reject messages (and so far haven't rejected any in this > thread), but let's please only post when we have something valuable to > add, which also fits the topic of this list. In this thread, when > you're not CC'ing the OP (which I've re-added here), they probably won't > even see your comments. > > On Wed, Nov 08, 2023 at 12:46:13PM -0800, Jean Luc Picard wrote: >> I have a number of natsec-ey google reports that went nowhere didnt't get >> credit or a dime out of it. Most are nullified by the current state of >> affairs struck by xAI (ie how to cook crack) but others I still feel should >> be looked at by the greater community. Is this the apprapriate aggregate >> platform now? > > You write "natsec-ey". That feels off-topic here. So is your message > actually off-topic and should have been rejected? No need to reply, > just please apply the "is my message on-topic" filter before you post. > > In general, if you've found something valuable, just share it where > appropriate - if it's a vulnerability in Open Source software, please > post in here. You don't need a CVE for this, nor any CVE alternative. > > On Wed, Nov 08, 2023 at 03:55:53PM -0500, Brian Peters wrote: >> What about NVID? NVID-2023-0001 >> Not (A) Vulnerability ID > > Now that reads like pun on NIST's NVD. > > We can come up with lots of other suggested names (and I had made some > suggestions too), but I think we don't need to continue much further. > > So let's wind this thread down unless there's something truly new and > on-topic to add. I'll start rejecting messages if I have to. > > Alexander
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.