haskell/security-advisories

Add initial content

TristanCacqueray opened this issue ยท 5 comments

The goal is to add some real advisory for known or past issue.

  • Follow the documentation and propose new advisory.
  • Update documentation if necessary.

Search of NVD/mitre turned up the following CVEs:

Reviewing those and reflecting them into the advisory-db would be a good start.

@david-christiansen has a known TOML lib issue (already fixed) that he will submit next week. (#56)

Re https://nvd.nist.gov/vuln/detail/CVE-2021-30502 vscode-ghc-simple RCE - it is actually not a Haskell program.

And it has been fixed in the latest version. I don't think there's anything further the SRT has to do for this issue.

+1, I don't think we have to do anything more for this one

I think we're done here :) All the known historical advisories have been added to the DB.