Skip to content

Consider using GitHub Action #457

Description

@tschmidtb51

💡 Summary

Use the GitHub CSAF Action to create consistent CSAF distribution.

Motivation and context

Currently, the publication seems to be self-build and is hosted through GitHub RAW user content. Unfortunately, some errors occur during the process (e.g. #454, #407, #387, #341, #334, #315, #307, #289, #265, #237,...)

This would be useful because

  • it creates hashes during the upload process
  • can work with already signed advisories
  • provide the retrieval via GitHub Pages (which delivers a Content-Type for JSON instead of text/plain)
  • makes sure the provider is compliant
  • rejects invalid CSAFs

Implementation notes

Please reach out to @bernhardreiter for implementation support if needed.
Feel free to open issues at https://github.com/csaf-tools/csaf-action/issues for any questions.

Acceptance criteria

How do we know when this work is done?

  • Usage of the action
  • Usage of GH-Pages

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions