skip to content

Publishing & Disclosure

Your duties as somebody else's upstream: how you publish, how you retract a bad release, how a report reaches you, what you owe downstream after a compromise. Few engineers reason as the upstream.

on this pageshow

explore

questions

page 2 of 2

How do you migrate forty packages from one shared publish token to trusted publishing?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Inventory where the shared credential lives and what else it grants, order the cutover by consumer impact, migrate each package to a publisher bound to one repository and workflow, and treat deleting the shared token as the completion criterion.

open as a page

A widely used internal package version has a serious flaw — when is withdrawing it worse than deprecating it?

level: principalimportance: nice to knowfreq 29%

basics

~20 s

Withdrawal is itself an outage: removing a version breaks every build, rebuild and rollback that references it across the estate. Prefer flagging plus a fixed replacement, and reserve hard removal for artifacts whose availability is the hazard.

open as a page

When should your company become a CNA rather than requesting CVE IDs through a root CNA?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Become a CNA when your advisory volume justifies a permanently staffed function; it buys control of timing and record content. Below that, requesting identifiers through a root is cheaper and avoids commitments you would fail to meet.

open as a page

One of six vendors cannot meet the agreed multi-party disclosure date. Do you extend for everyone?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Extending trades five vendors' users staying exposed longer against one vendor's users being exposed at publication. Decide against a rule agreed at the start: one short extension for a genuine engineering constraint, otherwise publish on the date.

open as a page

Which supported release lines get the security backport, and how do you decide?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Start from a support policy written before the incident, then narrow by evidence: whether the flaw exists and is reachable in each line, whether a safe patch is possible, and whether that line's users can deploy it in time.

open as a page

Leadership wants a paid bug bounty before you have a VDP or a PSIRT — what do you advise?

level: principalimportance: nice to knowfreq 34%

basics

~10 s

Publish and staff a vulnerability disclosure policy first. A bounty multiplies inbound reports without creating anyone to triage or fix them; the binding constraint is response and remediation capacity, not researcher supply.

open as a page

Re-publishing under a new signing identity breaks every consumer's pinned trust — when is that worth it?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Only when the old identity cannot be reclaimed. Changing identity forces every consumer to update a pin by hand, you cannot verify that they did, and slow ones stall for months. If the account is recovered and the attacker's path closed, keep the identity and rotate underneath it.

open as a page

showing 31–37 of 37