Skip to content

GHSA SYNC: 2 brand new advisories#768

Merged
postmodern merged 1 commit intorubysec:masterfrom
jasnow:ghsa-syncbot-2024-03-18-18_12_09
Mar 19, 2024
Merged

GHSA SYNC: 2 brand new advisories#768
postmodern merged 1 commit intorubysec:masterfrom
jasnow:ghsa-syncbot-2024-03-18-18_12_09

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Mar 18, 2024

GHSA SYNC: 2 brand new advisories:

@postmodern postmodern merged commit 35ca69b into rubysec:master Mar 19, 2024
@flavorjones
Copy link
Contributor

@jasnow @postmodern I think the introduction of gems/nokogiri/https://github.com/advisories/GHSA-vcc3-rw6f-jv97.yml is a duplicate of the GHSA I updated in #765

I don't understand why there are now two GHSAs that are identical in the github database, does anybody know?

@postmodern
Copy link
Member

Hmm, appears the GHSA ID is wrong and doesn't match the URL. https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-vcc3-rw6f-jv97 is 404ed.

@flavorjones
Copy link
Contributor

flavorjones commented Mar 20, 2024

Ah weird, the URL was definitely valid yesterday when I commented -- I wonder if github did some de-duping in the meantime? Anyway, thanks for removing it.

@jasnow jasnow deleted the ghsa-syncbot-2024-03-18-18_12_09 branch March 20, 2024 10:56
@jasnow
Copy link
Contributor Author

jasnow commented Mar 20, 2024

Here is the GHSA advisory: GHSA-vcc3-rw6f-jv97

Will add it to my "ignore" GHSA list.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants