Proposal: request CVEs as soon as possible, not after the advisory embargo date

Hi,

Context

The security policy says that we should wait for the embargo date of a security advisory to pass, and then request a CVE from GitHub, and then publish.

Problem

GitHub can take some time to issue a CVE (they say usually 72h but more has been observed these days (example), probably following all these AI security reports, see also GitHub’s blog post on this).

It seems to me that requesting a CVE ahead of time, as soon as we know we want to issue an advisory, would help make ourselves more predictable in following our three month disclosure policy.

Proposal

Change the security policy procedure to request a CVE as soon as we know we will issue the advisory. When the embargo date passes, we only have to hit publish.

+1, those delays have been a huge pain lately

+1 thanks

+1

Thanks,
Marius

+1, thanks

+1 as well, thanks

I just edited the policy to request the CVE when the advisory is complete, see: https://dev.xwiki.org/xwiki/bin/view/Community/SecurityPolicy/?viewer=changes&rev1=52.1&rev2=53.1&

thank you all for the +1 and @surli for the edit!