Skip to content

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Jan 13, 2026

GHSA SYNC: 2 modified advisories; 4 brand new advisories:

Modified:

New:

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Just spotted one issue where NVD mentions 2.3.0 being vulnerable. Also all of these GHSA url:s are still Unreviewed and missing package information that NVD has. We should switch those url:s to point to NVD.

Updated CVE-2011-4121 YAML file to change the URL to the NVD.
Updated the CVE URL to point to NVD instead of GitHub.
Updated the URL for CVE-2016-2339 to point to NVD.
@jasnow jasnow changed the title GHSA SYNC: 2 modified advisories; 4 brand new advisories GHSA SYNC: 2 modified advisories; 3 brand new advisories Jan 13, 2026
@jasnow
Copy link
Contributor Author

jasnow commented Jan 13, 2026

@postmodern - Add review changes have been addressed.

@postmodern postmodern merged commit 0a7f663 into rubysec:master Jan 13, 2026
1 check passed
@jasnow jasnow deleted the ghsa-syncbot-2026-01-12-19_34_57 branch January 13, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants