Skip to content

GHSA SYNC: 1 brand new advisory - #970

Merged
postmodern merged 16 commits into
rubysec:masterfrom
jasnow:two-more-rubies-advsr
Feb 13, 2026
Merged

GHSA SYNC: 1 brand new advisory#970
postmodern merged 16 commits into
rubysec:masterfrom
jasnow:two-more-rubies-advsr

Conversation

@jasnow

@jasnow jasnow commented Jan 23, 2026

Copy link
Copy Markdown
Member

GHSA SYNC: 1 brand new advisory

Comment thread rubies/mruby/CVE-2025-7207.yml Outdated
Comment thread rubies/mruby/CVE-2025-7207.yml Outdated
Comment thread rubies/ruby/CVE-2024-27282.yml
Removed a non-functional link from the CVE YAML file.
Updated notes to clarify that mruby 3.5.0 has not been released as of 1/23/2026.
@jasnow
jasnow requested a review from postmodern January 31, 2026 13:25
@jasnow jasnow changed the title GHSA SYNC: 1 enhanced and 1 brand new advisory GHSA SYNC: 1 brand new advisory Jan 31, 2026
@jasnow

jasnow commented Jan 31, 2026

Copy link
Copy Markdown
Member Author

Now deleted.

@postmodern

Copy link
Copy Markdown
Member

GitHub is saying rubies/ruby/CVE-2024-27282.yml has conflicting changes now and won't let me resolve them.

@jasnow

jasnow commented Feb 8, 2026

Copy link
Copy Markdown
Member Author

All green - now try it again.

@postmodern postmodern left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Need clarification on something. The advisory description mentions that the vulnerability was found in versions "up to 3.4.0-rc2". However, version 3.4.0 was tagged after 3.4.0-rc2. Is this a mistake and should it say "up to and including 3.4.0", or was the vulnerability actually fixed in 3.4.0?

@jasnow

jasnow commented Feb 8, 2026

Copy link
Copy Markdown
Member Author

back online - will check

Clarify that ISS#6509 is going into 3.5.0 (yet to be released)
@jasnow

jasnow commented Feb 8, 2026

Copy link
Copy Markdown
Member Author

I expect the patch to be part of 3.5.0 when it is released.

@postmodern postmodern left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wording changes requested, if you agree.

Comment thread rubies/mruby/CVE-2025-7207.yml Outdated
Comment thread rubies/mruby/CVE-2025-7207.yml Outdated
Comment thread rubies/mruby/CVE-2025-7207.yml Outdated
Comment thread rubies/mruby/CVE-2025-7207.yml Outdated
url:
- https://nvd.nist.gov/vuln/detail/CVE-2025-7207
- https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9.patch
- https://github.com/mruby/mruby/blob/master/NEWS.md

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The old URL is still there.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fix is only in master.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We already link to https://github.com/mruby/mruby/blob/6f321251785c2396cb7e6a576ac2080c1adb4491/NEWS.md above which is a commit in the master branch, so linking directly to the NEWS.md in the master branch is a duplicate URL. We shouldn't link to the same file twice.

Comment thread rubies/mruby/CVE-2025-7207.yml Outdated

@postmodern postmodern left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noticed some YAML issues. Also, the old NEWS.md URL is still listed. Also, not sure why the mruby 3.4.0 and 3.3.0 blog posts are listed as well?

Comment thread rubies/mruby/CVE-2025-7207.yml Outdated
url:
- https://nvd.nist.gov/vuln/detail/CVE-2025-7207
- https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9.patch
- https://github.com/mruby/mruby/blob/master/NEWS.md

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The old URL is still there.

Comment thread rubies/mruby/CVE-2025-7207.yml Outdated
Comment thread rubies/mruby/CVE-2025-7207.yml
@postmodern postmodern added linting YAML Linting and removed need clarification linting YAML Linting labels Feb 9, 2026
Comment thread rubies/mruby/CVE-2025-7207.yml Outdated
Comment thread rubies/mruby/CVE-2025-7207.yml Outdated
url:
- https://nvd.nist.gov/vuln/detail/CVE-2025-7207
- https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9.patch
- https://github.com/mruby/mruby/blob/master/NEWS.md

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We already link to https://github.com/mruby/mruby/blob/6f321251785c2396cb7e6a576ac2080c1adb4491/NEWS.md above which is a commit in the master branch, so linking directly to the NEWS.md in the master branch is a duplicate URL. We shouldn't link to the same file twice.

@postmodern
postmodern merged commit a888ef6 into rubysec:master Feb 13, 2026
1 check passed
@postmodern

Copy link
Copy Markdown
Member

Removed the duplicate NEWS.md URL myself.

@jasnow

jasnow commented Feb 13, 2026

Copy link
Copy Markdown
Member Author

Removed the duplicate NEWS.md URL myself.

Thanks

@jasnow
jasnow deleted the two-more-rubies-advsr branch February 13, 2026 01:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants