Hi sebb,

On 10.08.2026 09:39, sebb wrote:
> On Mon, 10 Aug 2026 at 07:48, Piotr P. Karwasz
> <[email protected]> wrote:
>> All the CVEs disclosed by the ASF *must* have a `vendor-advisory` link,
>> which most often than not is a link to the PonyMail archive:
>>
>> https://www.cve.org/CVERecord?id=CVE-2026-64607
> 
> Which suggests that such queries should be directed to the
> Httpcomponents project...


Yes, I saw that Gary posted the question to the wrong list. I just
wanted to point out that the answer to the question doesn't depend on
the PMC: all PMCs must include a `vendor-advisory`, otherwise the CVE
can not be switched to a PUBLIC state.

Piotr

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to