Skip to content

GHSA SYNC: 1 brand new advisory#970

Merged
postmodern merged 16 commits intorubysec:masterfrom
jasnow:two-more-rubies-advsr
Feb 13, 2026
Merged

GHSA SYNC: 1 brand new advisory#970
postmodern merged 16 commits intorubysec:masterfrom
jasnow:two-more-rubies-advsr

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Jan 23, 2026

GHSA SYNC: 1 brand new advisory

Removed a non-functional link from the CVE YAML file.
Updated notes to clarify that mruby 3.5.0 has not been released as of 1/23/2026.
@jasnow jasnow requested a review from postmodern January 31, 2026 13:25
@jasnow jasnow changed the title GHSA SYNC: 1 enhanced and 1 brand new advisory GHSA SYNC: 1 brand new advisory Jan 31, 2026
@jasnow
Copy link
Contributor Author

jasnow commented Jan 31, 2026

Now deleted.

@postmodern
Copy link
Member

GitHub is saying rubies/ruby/CVE-2024-27282.yml has conflicting changes now and won't let me resolve them.

@jasnow
Copy link
Contributor Author

jasnow commented Feb 8, 2026

All green - now try it again.

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Need clarification on something. The advisory description mentions that the vulnerability was found in versions "up to 3.4.0-rc2". However, version 3.4.0 was tagged after 3.4.0-rc2. Is this a mistake and should it say "up to and including 3.4.0", or was the vulnerability actually fixed in 3.4.0?

@jasnow
Copy link
Contributor Author

jasnow commented Feb 8, 2026

back online - will check

Clarify that ISS#6509 is going into 3.5.0 (yet to be released)
@jasnow
Copy link
Contributor Author

jasnow commented Feb 8, 2026

I expect the patch to be part of 3.5.0 when it is released.

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wording changes requested, if you agree.

url:
- https://nvd.nist.gov/vuln/detail/CVE-2025-7207
- https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9.patch
- https://github.com/mruby/mruby/blob/master/NEWS.md
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The old URL is still there.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fix is only in master.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We already link to https://github.com/mruby/mruby/blob/6f321251785c2396cb7e6a576ac2080c1adb4491/NEWS.md above which is a commit in the master branch, so linking directly to the NEWS.md in the master branch is a duplicate URL. We shouldn't link to the same file twice.

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noticed some YAML issues. Also, the old NEWS.md URL is still listed. Also, not sure why the mruby 3.4.0 and 3.3.0 blog posts are listed as well?

url:
- https://nvd.nist.gov/vuln/detail/CVE-2025-7207
- https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9.patch
- https://github.com/mruby/mruby/blob/master/NEWS.md
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The old URL is still there.

@postmodern postmodern added linting YAML Linting and removed need clarification linting YAML Linting labels Feb 9, 2026
url:
- https://nvd.nist.gov/vuln/detail/CVE-2025-7207
- https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9.patch
- https://github.com/mruby/mruby/blob/master/NEWS.md
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We already link to https://github.com/mruby/mruby/blob/6f321251785c2396cb7e6a576ac2080c1adb4491/NEWS.md above which is a commit in the master branch, so linking directly to the NEWS.md in the master branch is a duplicate URL. We shouldn't link to the same file twice.

@postmodern postmodern merged commit a888ef6 into rubysec:master Feb 13, 2026
1 check passed
@postmodern
Copy link
Member

Removed the duplicate NEWS.md URL myself.

@jasnow
Copy link
Contributor Author

jasnow commented Feb 13, 2026

Removed the duplicate NEWS.md URL myself.

Thanks

@jasnow jasnow deleted the two-more-rubies-advsr branch February 13, 2026 01:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants