Skip to content

Conversation

@G-Rath
Copy link
Collaborator

@G-Rath G-Rath commented Nov 27, 2025

This should make it possible for folks like GitHub to ingest our advisories and in turn have tools like dependabot do automatic updates, as while they technically use OSV as their advisory format, they rely a lot more heavily on the ecosystem for matching packages to their sources

@G-Rath G-Rath marked this pull request as ready for review December 3, 2025 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants