Skip to content

GHSA SYNC: 1 brand new advisory#970

Open
jasnow wants to merge 8 commits intorubysec:masterfrom
jasnow:two-more-rubies-advsr
Open

GHSA SYNC: 1 brand new advisory#970
jasnow wants to merge 8 commits intorubysec:masterfrom
jasnow:two-more-rubies-advsr

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Jan 23, 2026

GHSA SYNC: 1 brand new advisory

Removed a non-functional link from the CVE YAML file.
Updated notes to clarify that mruby 3.5.0 has not been released as of 1/23/2026.
@jasnow jasnow requested a review from postmodern January 31, 2026 13:25
@jasnow jasnow changed the title GHSA SYNC: 1 enhanced and 1 brand new advisory GHSA SYNC: 1 brand new advisory Jan 31, 2026
@jasnow
Copy link
Contributor Author

jasnow commented Jan 31, 2026

Now deleted.

@postmodern
Copy link
Member

GitHub is saying rubies/ruby/CVE-2024-27282.yml has conflicting changes now and won't let me resolve them.

@jasnow
Copy link
Contributor Author

jasnow commented Feb 8, 2026

All green - now try it again.

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Need clarification on something. The advisory description mentions that the vulnerability was found in versions "up to 3.4.0-rc2". However, version 3.4.0 was tagged after 3.4.0-rc2. Is this a mistake and should it say "up to and including 3.4.0", or was the vulnerability actually fixed in 3.4.0?

@jasnow
Copy link
Contributor Author

jasnow commented Feb 8, 2026

back online - will check

Clarify that ISS#6509 is going into 3.5.0 (yet to be released)
@jasnow
Copy link
Contributor Author

jasnow commented Feb 8, 2026

I expect the patch to be part of 3.5.0 when it is released.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants