-
-
Notifications
You must be signed in to change notification settings - Fork 227
GHSA SYNC: Advisories (2 mruby and 1 mrubyc brand new) plus schema change #971
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
GHSA SYNC: Advisories (2 mruby and 1 mrubyc brand new) plus schema change #971
Conversation
postmodern
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We need to decide on a policy for when a patched version has not yet been released. Do we A) list the upcoming future version number B) omit patched_versions: to indicate that no official version is considered patched? I personally think it's confusing to instruct users to upgrade to a version that does not exist yet.
| cvss_v3: 7.8 | ||
| cvss_v4: 4.8 | ||
| patched_versions: | ||
| - ">= 3.5.0" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Oops. mruby 3.5.0 has not been released yet. patched_versions: should be omitted until 3.5.0 is released. Instructing users to upgrade to a version that does not exist yet is not helpful.
| cvss_v3: 5.5 | ||
| cvss_v4: 4.8 | ||
| patched_versions: | ||
| - ">= 3.5.0" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Oops. mruby 3.5.0 has not been released yet. patched_versions: should be omitted until 3.5.0 is released. Instructing users to upgrade to a version that does not exist yet is not helpful.
|
I suggest we use the notes: "Never patched" line in place of the patched_versions field (just like in the |
I am not a fan of |
GHSA SYNC: Advisories (2 mruby and 1 mrubyc brand new) plus schema change