Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: document "Publishing updates to advisories"

...

Apache Logging publishes VDR as an external BOM: see https://www.sonatype.com/blog/sbom-vdr-and-maven-transforming-the-apache-logging-experience-to-a-common-pattern for details on the pattern

Publishing updates to advisories

Updates to already-published advisories are allowed, but limited: we want to avoid situations where downstream users have already 'dismissed' the advisory based on the 'old' information, and may miss the 'new' information. For that reason, you cannot:

  • Widen affected version ranges
  • Increase severity ratings
  • Add additional necessary mitigation steps

If you discover such information after publication, you publish a follow-up advisory to make sure downstream users see it.

For other changes, such as clarifications to the description or refining weakness type classifications, you can make updates in the cveprocess tool and ping security@apache.org to get your change published.