Skip to content

[GHSA-xcpc-8h2w-3j85] Re-apply fixed-version correction in details (0.5.18 -> 0.6.0) - #9034

Open
pacocartones wants to merge 1 commit into
github:pacocartones/advisory-improvement-9034from
pacocartones:pacocartones-GHSA-xcpc-8h2w-3j85-fix-revert
Open

[GHSA-xcpc-8h2w-3j85] Re-apply fixed-version correction in details (0.5.18 -> 0.6.0)#9034
pacocartones wants to merge 1 commit into
github:pacocartones/advisory-improvement-9034from
pacocartones:pacocartones-GHSA-xcpc-8h2w-3j85-fix-revert

Conversation

@pacocartones

Copy link
Copy Markdown

Summary

Re-applies the details fixed-version correction from #8694 (merged 2026-07-17), which was reverted when this advisory was promoted from unreviewed to github-reviewed on the same day.

What was lost

#8694 corrected details from "adm-zip before 0.5.18" to "adm-zip before 0.6.0", matching the fixed version. When the advisory was promoted to github-reviewed on 2026-07-17 (updating advisories/github-reviewed/2026/07/GHSA-xcpc-8h2w-3j85/GHSA-xcpc-8h2w-3j85.json), the corrected affected range (fixed: 0.6.0) was kept, but details reverted to "before 0.5.18".

As a result, the advisory on main is currently internally inconsistent: affected[].ranges[].events[].fixed says 0.6.0, while details says "before 0.5.18".

Change

One line in details: "before 0.5.18" -> "before 0.6.0", identical to the text already reviewed and merged in #8694. No other fields are touched.

@github-actions
github-actions Bot changed the base branch from main to pacocartones/advisory-improvement-9034 August 9, 2026 20:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant