Skip to content

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Jan 24, 2026

GHSA SYNC: Advisories (2 mruby and 1 mrubyc brand new) plus schema change

@jasnow jasnow changed the title GHSA SYNC: 2 mruby and 1 mrubyc brand new advisory plus schema change GHSA SYNC: Advisories (2 mruby and 1 mrubyc brand new) plus schema change Jan 24, 2026
@postmodern postmodern merged commit 8ba0f94 into rubysec:master Jan 31, 2026
1 check passed
Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need to decide on a policy for when a patched version has not yet been released. Do we A) list the upcoming future version number B) omit patched_versions: to indicate that no official version is considered patched? I personally think it's confusing to instruct users to upgrade to a version that does not exist yet.

cvss_v3: 7.8
cvss_v4: 4.8
patched_versions:
- ">= 3.5.0"
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oops. mruby 3.5.0 has not been released yet. patched_versions: should be omitted until 3.5.0 is released. Instructing users to upgrade to a version that does not exist yet is not helpful.

cvss_v3: 5.5
cvss_v4: 4.8
patched_versions:
- ">= 3.5.0"
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oops. mruby 3.5.0 has not been released yet. patched_versions: should be omitted until 3.5.0 is released. Instructing users to upgrade to a version that does not exist yet is not helpful.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants