|
|
We've written most of our tools to handle CVE-\d+-\d+ already, so "extra digits" is our preferred option, and out of those a preference would be a fixed number of digits with leading 0s to reduce c&p errors. Thanks, Mark -- Mark J Cox / Senior Director, Security Engineering, Red Hat