mozilla/foundation-security-advisories

Provice RSS Feed and/or ml annoucment

klausenbusk opened this issue · 5 comments

I want to be notified when a new security release is available, but there isn't anyway to be notified.

A RSS Feed or a ml announcement could be useful.

pmac commented

We do have a JSON feed in the format that MITRE requires. I'm not sure if it's what you need, but it could be used to do what you need I think.

https://www.mozilla.org/en-US/security/advisories/cve-feed.json

We do have a JSON feed in the format that MITRE requires. I'm not sure if it's what you need, but it could be used to do what you need I think.

That could work, thanks! I do find it a bit strange though, that security issue/dot releases isn't announced. How is ex Linux distros supposed to know when a new version is available?

pmac commented

You mean other than the release notes we publish for every version when they're released?

https://www.mozilla.org/en-US/firefox/releases/

Or the public site that has all kinds of data on our releases?

https://product-details.mozilla.org/1.0/

You mean other than the release notes we publish for every version when they're released?

What I meant was: There is no way to be notified when a new release is released, you either need to visit or scrap https://www.mozilla.org/en-US/firefox/releases/ regularly, that isn't ideal.

Release management is discussing this and will likely post an update in https://bugzilla.mozilla.org/show_bug.cgi?id=1589656.