Skip to content

Conversation

@piyush-jena
Copy link
Contributor

@piyush-jena piyush-jena commented Nov 19, 2025

Description of changes:
This PR adds a github workflow that validates the fields in a BRSA.

  • It first checks for changed files in the advisories directory. For each changed advisory it extracts package metadata and then verifies it from the rpmspec of that package. The implementation won't work if BRSAs are created for sub-packages because the spec file couldn't be found for that case.

Some changes that will be added:

  1. Currently it only checks changed files in the staging directory
  2. Checkout older tag if BRSA is added/updated in a non-staging directory

Testing done:

  1. Added hack commit to show its working.

Terms of contribution:

By submitting this pull request, I agree that this contribution is dual-licensed under the terms of both the Apache License, version 2.0, and the MIT license.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant