GHSA/SYNC: 1 brand new rails-related advisory#1020
Conversation
|
I don't think this is right. It's saying 8.0.5 is not patched |
|
@jasnow https://rubyonrails.org/2026/3/24/Rails-Versions-8-0-5-and-8-1-3-have-been-released |
|
|
@jasnow then shouldn't line 19 be
|
|
My guess is that it follows: https://guides.rubygems.org/patterns/ and it is called pessimistic version constraint. |
|
I'm confused. I'm saying that this PR is not correct and was hoping you'd update the file. Do you want me to open a fix? |
what's wrong with it? |
|
See screenshot below. 8.0.5 should not be considered vulnerable for this CVE. If you look at the affected versions on the CVE (GHSA-p9fm-f462-ggrg), 8.0.5 doesn't fall into any of those ranges. I think line 19 in the PR should change, probably as per my comment above:
|
|
I will let @postmodern answer this question. |
|
I am going to change the |
* activestorage 8.0.5 and 8.1.3 are considered patched. https://rubyonrails.org/2026/3/24/Rails-Versions-8-0-5-and-8-1-3-have-been-released

GHSA/SYNC: 1 brand new rails-related advisory
* gems/activestorage/CVE-2026-33658.yml