Skip to content

GHSA SYNC: 1 brand new advisory#970

Open
jasnow wants to merge 12 commits intorubysec:masterfrom
jasnow:two-more-rubies-advsr
Open

GHSA SYNC: 1 brand new advisory#970
jasnow wants to merge 12 commits intorubysec:masterfrom
jasnow:two-more-rubies-advsr

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Jan 23, 2026

GHSA SYNC: 1 brand new advisory

Removed a non-functional link from the CVE YAML file.
Updated notes to clarify that mruby 3.5.0 has not been released as of 1/23/2026.
@jasnow jasnow requested a review from postmodern January 31, 2026 13:25
@jasnow jasnow changed the title GHSA SYNC: 1 enhanced and 1 brand new advisory GHSA SYNC: 1 brand new advisory Jan 31, 2026
@jasnow
Copy link
Contributor Author

jasnow commented Jan 31, 2026

Now deleted.

@postmodern
Copy link
Member

GitHub is saying rubies/ruby/CVE-2024-27282.yml has conflicting changes now and won't let me resolve them.

@jasnow
Copy link
Contributor Author

jasnow commented Feb 8, 2026

All green - now try it again.

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Need clarification on something. The advisory description mentions that the vulnerability was found in versions "up to 3.4.0-rc2". However, version 3.4.0 was tagged after 3.4.0-rc2. Is this a mistake and should it say "up to and including 3.4.0", or was the vulnerability actually fixed in 3.4.0?

@jasnow
Copy link
Contributor Author

jasnow commented Feb 8, 2026

back online - will check

Clarify that ISS#6509 is going into 3.5.0 (yet to be released)
@jasnow
Copy link
Contributor Author

jasnow commented Feb 8, 2026

I expect the patch to be part of 3.5.0 when it is released.

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wording changes requested, if you agree.

url:
- https://nvd.nist.gov/vuln/detail/CVE-2025-7207
- https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9.patch
- https://github.com/mruby/mruby/blob/master/NEWS.md
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The old URL is still there.

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noticed some YAML issues. Also, the old NEWS.md URL is still listed. Also, not sure why the mruby 3.4.0 and 3.3.0 blog posts are listed as well?

url:
- https://nvd.nist.gov/vuln/detail/CVE-2025-7207
- https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9.patch
- https://github.com/mruby/mruby/blob/master/NEWS.md
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The old URL is still there.

- https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9.patch
- https://github.com/mruby/mruby/blob/master/NEWS.md
- https://mruby.org/releases/2025/04/20/mruby-3.4.0-released.html
- https://mruby.org/releases/2024/02/14/mruby-3.3.0-released.html
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just curious why the 3.4.0 and 3.3.0 blog posts are listed as they do not fix issue 6509 or even mention it?

notes: |
- Not patched - mruby 3.5.0 has not been released as of 2026/02/07.
- Found Issue #6509 listed in **unreleased** mruby 3.5 file listed below.
url:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Appears that related: disappeared? This causes url: to be consumed by notes: | above.

@postmodern postmodern added linting YAML Linting and removed need clarification linting YAML Linting labels Feb 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants