GHSA SYNC: Advisories (2 mruby and 1 mrubyc brand new) plus schema change#971
Conversation
postmodern
left a comment
There was a problem hiding this comment.
We need to decide on a policy for when a patched version has not yet been released. Do we A) list the upcoming future version number B) omit patched_versions: to indicate that no official version is considered patched? I personally think it's confusing to instruct users to upgrade to a version that does not exist yet.
| cvss_v3: 7.8 | ||
| cvss_v4: 4.8 | ||
| patched_versions: | ||
| - ">= 3.5.0" |
There was a problem hiding this comment.
Oops. mruby 3.5.0 has not been released yet. patched_versions: should be omitted until 3.5.0 is released. Instructing users to upgrade to a version that does not exist yet is not helpful.
| cvss_v3: 5.5 | ||
| cvss_v4: 4.8 | ||
| patched_versions: | ||
| - ">= 3.5.0" |
There was a problem hiding this comment.
Oops. mruby 3.5.0 has not been released yet. patched_versions: should be omitted until 3.5.0 is released. Instructing users to upgrade to a version that does not exist yet is not helpful.
|
I suggest we use the notes: "Never patched" line in place of the patched_versions field (just like in the |
I am not a fan of |
GHSA SYNC: Advisories (2 mruby and 1 mrubyc brand new) plus schema change