Comment by masklinn
9 hours ago
That is exactly why many big projects are migrating to becoming CNA, so that randos can’t get assigned unqualified CVEs which nobody has looked at or validated.
Apparently RedHat is a CNA of last resort, so it might be possible to get your project under Redhat’s scope and go through them without having to be a CNA yourself.
What are the requirements to become a CNA?
The OSSF (Open Source Security Foundation) has a nice guide on how to become a CNA [0]. It's pretty involved though.
[0] https://github.com/ossf/wg-vulnerability-disclosures/blob/ma...