THREATOPS
THREAT OPSThreat News › Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely

Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely

lowoss_secPublished 2026-08-27

<p>Posted by Syed on Aug 26</p>This is a measurement, not a vulnerability report.<br /> <br /> The CVE v5 format defines a `credits` container naming who found or<br /> reported an<br /> issue, with typed roles. The OSV schema defines an equivalent field. GitHub<br /> collects credit from reporters, requires them to accept it before display,<br /> shows<br /> it on the advisory page, and serves it

Original source: https://seclists.org/oss-sec/2026/q3/597