Skip to content

GHSA SYNC: 4 enhanced ruby advisories and 2 new ruby advisories#997

Merged
postmodern merged 5 commits intorubysec:masterfrom
jasnow:ghsa-syncbot-2026-02-14-14_17_44
Feb 15, 2026
Merged

GHSA SYNC: 4 enhanced ruby advisories and 2 new ruby advisories#997
postmodern merged 5 commits intorubysec:masterfrom
jasnow:ghsa-syncbot-2026-02-14-14_17_44

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Feb 14, 2026

GHSA SYNC: 4 enhanced ruby advisories and 2 new ruby advisories

Modified

New:

jasnow and others added 5 commits February 14, 2026 14:19
….yml`.

* Any reviewer notes should go under the `notes:` key.
…7-6181.yml`

* Additional notes or internal commentary that are not in the original advisory should not be added to `description:`.
…yml`

* Additional reviewer notes should go under the `notes:` key.
Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please do not add additional Note: or RELEASE NOTE comments to description:, unless they appear in the original advisory text. Any internal review comments should go under notes:.

I went ahead and deleted them. If you want to preserve them, close and re-submit the PR but with the notes under a notes: | key. If you're OK with them being deleted, I will go ahead and squash merge the PR.

@postmodern
Copy link
Member

Also I still do not understand why an empty line sometimes appears in the middle of the related: url: list. This is the second time I've seen that in your GitHub Sync PRs. The GitHub Sync script sets that field to the GHSA references Array. If the URL was null then YAML would still add a - line. If the URL ended with a newline character, YAML would wrap the String in single quotes. Please check for random empty lines in related: url: and remove them.

@jasnow
Copy link
Contributor Author

jasnow commented Feb 14, 2026

I accept your changes.

@jasnow
Copy link
Contributor Author

jasnow commented Feb 14, 2026

The GitHub Sync script sets that field to the GHSA references Array. If the URL was null then YAML would still add a - line. If the URL ended with a newline character, YAML would wrap the String in single quotes. Please check for random empty lines in related: url: and remove them.

FYI: All *rubies have been manually created or modified by me. The existing script only provides rubygems advisories.

@postmodern postmodern merged commit ceb1564 into rubysec:master Feb 15, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants