I'm putting together a list of big and small issues that makes us (the curl project) considering switching away from GitHub for security reporting/advisories again:

https://gist.github.com/bagder/ed3268e8745452a53a999d23b7fa1273

*considering* being the operative word, nothing has been decided and I think it's fair to give it some more time first. And some communication to see what can be done, fixed or adjusted.

To be continued.

GitHub Security Advisory wishlist from the curl project

GitHub Security Advisory wishlist from the curl project - GSA-wishlist.md

Gist
@bagder Where are you not seeing the number of advisories next to the "Security" tab? I can see it (5) on the sudo-rs repository, for example.
GitHub - trifectatechfoundation/sudo-rs: A memory safe implementation of sudo and su.

A memory safe implementation of sudo and su. Contribute to trifectatechfoundation/sudo-rs development by creating an account on GitHub.

GitHub
@ilmari I currently have 1 in triage and 2 in draft but the tab says "Security" (no counter)
@bagder Ah, I guess it only shows published advisories, even if you are logged in as a user who can se more?
@ilmari right, that's exactly my point. With issues and PRs we see a count of the list of "open" items, with advisories we do not