Publishing & Disclosure
Your duties as somebody else's upstream: how you publish, how you retract a bad release, how a report reaches you, what you owe downstream after a compromise. Few engineers reason as the upstream.
on this pageshowhide
explore
- Release Path Integrity12 questions
- Trusted Publishing4 questions
- Maintainer Account Hardening4 questions
- Yank, Deprecate or Delete4 questions
- Receiving Vulnerability Reports17 questions
- Vulnerability Disclosure Policy4 questions
- Coordinated Disclosure Embargo5 questions
- Issuing an Advisory4 questions
- Embargoed Patch Delivery4 questions
- Responding to Compromise8 questions
- Malicious Dependency Response4 questions
- Compromised Publishing Identity4 questions
questions
page 2 of 2A widely used internal package version has a serious flaw — when is withdrawing it worse than deprecating it?
basics
~20 sWithdrawal is itself an outage: removing a version breaks every build, rebuild and rollback that references it across the estate. Prefer flagging plus a fixed replacement, and reserve hard removal for artifacts whose availability is the hazard.
When should your company become a CNA rather than requesting CVE IDs through a root CNA?
basics
~20 sBecome a CNA when your advisory volume justifies a permanently staffed function; it buys control of timing and record content. Below that, requesting identifiers through a root is cheaper and avoids commitments you would fail to meet.
One of six vendors cannot meet the agreed multi-party disclosure date. Do you extend for everyone?
basics
~20 sExtending trades five vendors' users staying exposed longer against one vendor's users being exposed at publication. Decide against a rule agreed at the start: one short extension for a genuine engineering constraint, otherwise publish on the date.
Which supported release lines get the security backport, and how do you decide?
basics
~20 sStart from a support policy written before the incident, then narrow by evidence: whether the flaw exists and is reachable in each line, whether a safe patch is possible, and whether that line's users can deploy it in time.
Leadership wants a paid bug bounty before you have a VDP or a PSIRT — what do you advise?
basics
~10 sPublish and staff a vulnerability disclosure policy first. A bounty multiplies inbound reports without creating anyone to triage or fix them; the binding constraint is response and remediation capacity, not researcher supply.
Re-publishing under a new signing identity breaks every consumer's pinned trust — when is that worth it?
basics
~20 sOnly when the old identity cannot be reclaimed. Changing identity forces every consumer to update a pin by hand, you cannot verify that they did, and slow ones stall for months. If the account is recovered and the attacker's path closed, keep the identity and rotate underneath it.
showing 31–37 of 37