Security advisories sent to the Security-news mailing list include the link to the gitlab confidential issues
Security advisories sent to the Security-news mailing list include the link to the gitlab confidential issues. As security issues get a security private fork, this is not really leaking any confidential information: each security fork will be for a single issue, so the item id is always 1. You cannot even infer the number of open security issues. But it can be confusing having a link to a issue that you are not able to access, and it's not even rendered in the security advisory itself (even when you actually can access).
issue