Hi sebb, On 10.08.2026 09:39, sebb wrote: > On Mon, 10 Aug 2026 at 07:48, Piotr P. Karwasz > <[email protected]> wrote: >> All the CVEs disclosed by the ASF *must* have a `vendor-advisory` link, >> which most often than not is a link to the PonyMail archive: >> >> https://www.cve.org/CVERecord?id=CVE-2026-64607 > > Which suggests that such queries should be directed to the > Httpcomponents project...
Yes, I saw that Gary posted the question to the wrong list. I just wanted to point out that the answer to the question doesn't depend on the PMC: all PMCs must include a `vendor-advisory`, otherwise the CVE can not be switched to a PUBLIC state. Piotr --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
