Hi,
Context
The security policy says that we should wait for the embargo date of a security advisory to pass, and then request a CVE from GitHub, and then publish.
Problem
GitHub can take some time to issue a CVE (they say usually 72h but more has been observed these days (example), probably following all these AI security reports, see also GitHub’s blog post on this).
It seems to me that requesting a CVE ahead of time, as soon as we know we want to issue an advisory, would help make ourselves more predictable in following our three month disclosure policy.
Proposal
Change the security policy procedure to request a CVE as soon as we know we will issue the advisory. When the embargo date passes, we only have to hit publish.