Skip to content

GHSA SYNC: 2 new advisories; 3 modified advisories#989

Open
jasnow wants to merge 2 commits intorubysec:masterfrom
jasnow:ghsa-syncbot-2026-02-08-07_32_26
Open

GHSA SYNC: 2 new advisories; 3 modified advisories#989
jasnow wants to merge 2 commits intorubysec:masterfrom
jasnow:ghsa-syncbot-2026-02-08-07_32_26

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Feb 8, 2026

GHSA SYNC: 2 new advisories; 3 modified advisories

Added GitLab advisory URL:

New (also include GitLab advisory URL):

- https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/storefront/app/controllers/spree/orders_controller.rb#L51C1-L55C8
- https://github.com/spree/spree/blob/a878eb4a782ce0445d218ea86fb12075b0e3d7cc/core/lib/spree/core/number_generator.rb#L45
- https://github.com/advisories/GHSA-p6pv-q7rc-g4h9
- https://advisories.gitlab.com/pkg/gem/spree_storefront/GHSA-p6pv-q7rc-g4h9
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Now that gems/spree_storefront/CVE-2026-25757.yml has been added, we can delete gems/spree_storefront/GHSA-p6pv-q7rc-g4h9.yml as they reference the same GHSA.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Merge PR#585 and I would have catch this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants