Security Advisory

Standard process for turning a confirmed Hook0 vulnerability into a published security advisory and, where warranted, a CVE. Use whenever a security report is confirmed and a fix is being prepared or has shipped, or when the team asks to "publish an advisory", "request a CVE", "assign a CVE", "credit a researcher", or "handle a security disclosure". Covers the CVE decision, the GitHub Security Advisory draft, timing, doc updates, and crediting the reporter.

hook0 884e9ca 2 files · 6.4 KB Updated

File contents

hook0/hook0/tree/main/.claude/skills/security-advisory commit 884e9ca673

Frequently asked questions

npx skillmds@latest add hook0/security-advisory