Skip to content

Conversation

@llwslc
Copy link

@llwslc llwslc commented Nov 18, 2025

Updates

  • Affected products

Comments
Split into two affected-product entries to accurately represent independent fixes across the 10.x and 11.x maintenance lines — 10.5.0 patches the 10.x range and 11.1.0 patches the 11.x range.

@github
Copy link
Collaborator

github commented Nov 18, 2025

Hi there @isaacs! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copilot AI review requested due to automatic review settings November 18, 2025 07:48
@github-actions github-actions bot changed the base branch from main to llwslc/advisory-improvement-6430 November 18, 2025 07:49
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the security advisory GHSA-5j98-mcp5-4vw2 to split the affected version ranges for the glob package into two separate entries, accurately representing independent fixes across the 10.x and 11.x maintenance lines.

  • Splits single affected product entry into two distinct entries for glob 10.x and 11.x ranges
  • Adds version 10.5.0 as the fix for the 10.x line (10.3.7 to 10.4.5)
  • Retains version 11.1.0 as the fix for the 11.x line (11.0.0+)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@dargmuesli
Copy link

Duplicate of #6427?

@advisory-database advisory-database bot merged commit 89ba896 into llwslc/advisory-improvement-6430 Nov 18, 2025
10 checks passed
@advisory-database
Copy link
Contributor

Hi @llwslc! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the llwslc-GHSA-5j98-mcp5-4vw2 branch November 18, 2025 15:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants