Home / Companies / AuthZed / Blog / Post Details
Content Deep Dive

Using GitHub to manage your first CVE

Blog post from AuthZed

Post Details
Company
Date Published
Author
Joey Schorr
Word Count
2,483
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

The author was faced with a security issue in their open source project, SpiceDB, which involved a bug that had real-world consequences. The team created a GitHub Security Advisory to remediate the issue, which included creating a private fork of the repository, developing a fix, testing it, and publishing a CVE identifier. They also deployed the fix to production before publishing the advisory publicly. The process was smooth, despite some minor bumps, thanks to GitHub's Security Advisory system, which provided a formalized security vulnerability process for the project.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.