Merged
Conversation
Contributor
Author
|
Noticed the failing tests, will fix the data |
2ad06c1 to
92bb19a
Compare
- gems/Autolab/CVE-2024-49376.yml - gems/alchemy_cms/CVE-2018-18307.yml - gems/camaleon_cms/GHSA-3hp8-6j24-m5gm.yml - gems/fluentd-ui/CVE-2020-21514.yml - gems/fluentd/CVE-2020-21514.yml - gems/nokogiri/GHSA-fq42-c5rg-92c2.yml - gems/nokogiri/GHSA-gx8x-g87m-h5q6.yml - gems/nokogiri/GHSA-v6gp-9mmm-c6p5.yml - gems/nokogiri/GHSA-vcc3-rw6f-jv97.yml - gems/nokogiri/GHSA-xxx9-3xcr-gjj3.yml - gems/omniauth-saml/GHSA-cvp8-5r8g-fhvq.yml - gems/omniauth-saml/GHSA-hw46-3hmr-x9xv.yml - gems/rails/CVE-2024-26143.yml - gems/spree_auth_devise/GHSA-6mqr-q86q-6gwr.yml - gems/spree_auth_devise/GHSA-8xfw-5q82-3652.yml - gems/spree_auth_devise/GHSA-gpqc-4pp7-5954.yml - gems/user_agent_parser/GHSA-pcqq-5962-hvcw.yml - gems/webrick/CVE-2009-4492.yml
92bb19a to
659b10a
Compare
Contributor
Author
|
Ready for review now |
postmodern
requested changes
May 21, 2025
Member
postmodern
left a comment
There was a problem hiding this comment.
Have some questions about some of the advisories. Also some minor formatting corrections.
* remove duplicates of gems/nokogiri/CVE-2018-25032.yml: - gems/nokogiri/GHSA-v6gp-9mmm-c6p5.yml * remove duplicates of gems/nokogiri/CVE-2021-30560.yml: - gems/nokogiri/GHSA-fq42-c5rg-92c2.yml * remove duplicates of gems/nokogiri/CVE-2022-23437.yml: - gems/nokogiri/GHSA-xxx9-3xcr-gjj3.yml * remove duplicates of gems/nokogiri/CVE-2022-24839.yml: - gems/nokogiri/GHSA-gx8x-g87m-h5q6.yml * remove duplicates of gems/omniauth-saml/CVE-2024-45409.yml: - gems/omniauth-saml/GHSA-cvp8-5r8g-fhvq.yml * remove duplicates of gems/spree_auth_devise/CVE-2021-41275.yml: - gems/spree_auth_devise/GHSA-6mqr-q86q-6gwr.yml - gems/spree_auth_devise/GHSA-8xfw-5q82-3652.yml - gems/spree_auth_devise/GHSA-gpqc-4pp7-5954.yml * remove duplicates of gems/nokogiri/CVE-2022-23437.yml: - gems/nokogiri/GHSA-xxx9-3xcr-gjj3.yml * use `##` instead of `**` to denote sections within the description text * use `description: |` to make text easier to read and edit * use NVD url for gems/alchemy_cms/CVE-2018-18307.yml
Contributor
Author
|
@postmodern the pull request is ready to be reviewed again |
This advisory already exists at `gems/actionpack/CVE-2024-26143.yml`.
postmodern
requested changes
May 21, 2025
Member
postmodern
left a comment
There was a problem hiding this comment.
Noticed that Autolab doesn't appear to be on https://rubygems.org. Should that advisory be removed?
I also took the liberty of removing the duplicate gems/rails/ advisory, which already exists at gems/actionpack/CVE-2024-26143.yml.
Autolab is a standalone Ruby web-app and was never released as a gem.
Link to the GHSA advisory for CVE-2020-21514.
Link to the GHSA advisory for CVE-2020-21514.
tvdeyen
reviewed
Aug 29, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.