Skip to content

GHSA/SYNC: (Two new, updated 4, renamed 2, ignored 2) advisories - #1190

Merged
jasnow merged 8 commits into
rubysec:masterfrom
jasnow:ghsa-syncbot-2026-07-29-14_32_35
Jul 31, 2026
Merged

GHSA/SYNC: (Two new, updated 4, renamed 2, ignored 2) advisories#1190
jasnow merged 8 commits into
rubysec:masterfrom
jasnow:ghsa-syncbot-2026-07-29-14_32_35

Conversation

@jasnow

@jasnow jasnow commented Jul 29, 2026

Copy link
Copy Markdown
Member

GHSA/SYNC: (Two new, updated 4, renamed 2, ignored 2) advisories

@jasnow
jasnow requested a review from simi July 29, 2026 20:11
Comment thread gems/sqlite3/CVE-2026-54619.yml Outdated
Comment thread gems/sqlite3/CVE-2026-54620.yml
Comment thread gems/pagy/CVE-2026-54659.yml Outdated
@simi

simi commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Please remove or re-source the unaffected_versions: "< 2.1.0" entry in gems/sqlite3/CVE-2026-54619.yml. The current GitHub advisory data for GHSA-28hh-pr2h-2w89 says the sqlite3 gem is affected by <= 2.9.4, while only GHSA-j7fr-3v8c-3qc3 / CVE-2026-54620 is narrowed to >= 2.1.0, <= 2.9.4. If there is a stronger upstream source showing CVE-2026-54619 also excludes versions before 2.1.0, please link it in the PR before merge.

Removed unaffected_versions section from CVE-2026-54619.yml.

@flavorjones flavorjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just left a question about the new "ignores".

Comment thread lib/rad-ignores.sh
@jasnow
jasnow merged commit 4a871d6 into rubysec:master Jul 31, 2026
2 checks passed
@jasnow
jasnow deleted the ghsa-syncbot-2026-07-29-14_32_35 branch July 31, 2026 18:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants