Skip to content

Update GHSA-4mjq-hx99-8pp5.json to add two new patches for the same vulnerability #5573

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

zly123987
Copy link

Updates

  • References

Comments

@Copilot Copilot AI review requested due to automatic review settings May 20, 2025 07:49
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the advisory JSON file to include two new patch commit references for addressing the reported vulnerability.

  • Adds two new commit entries with links and summaries.
  • Updates the patch commit information to supplement the existing vulnerability reference.

{
"type": "WEB",
"url": "https://github.com/radareorg/radare2/commit/c40a4f9862104ede15d0ba05ccbf805923070778",
"summary": "The commit is a subsequent supplementary fix for the CVE."
Copy link
Preview

Copilot AI May 20, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nitpick] Consider updating the commit summary on this entry to differentiate its purpose from the other patch, especially given that the PR description implies one commit is an alternative fix.

Copilot uses AI. Check for mistakes.

{
"type": "WEB",
"url": "https://github.com/radareorg/radare2/commit/c35d1629422a12fafb0b3d379c8739c7894521e9",
"summary": "The commit is a subsequent supplementary fix for the CVE."
Copy link
Preview

Copilot AI May 20, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nitpick] If these two patch commits serve different roles (e.g., one as a supplementary fix and the other as an alternative fix), their summaries should clearly reflect that distinction.

Copilot uses AI. Check for mistakes.

@github-actions github-actions bot changed the base branch from main to zly123987/advisory-improvement-5573 May 20, 2025 07:50
@shelbyc
Copy link
Contributor

shelbyc commented May 20, 2025

Hi @zly123987, I'm closing the PR because GitHub can't review the advisory. radareorg/radare2 isn't in one of the GitHub Advisory Database's supported ecosystems. If you are interested in seeing this commit incorporated into the CVE references, you can request a change to the CVE record and contact MITRE, the assigning CNA, at https://cveform.mitre.org/.

@shelbyc shelbyc closed this May 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants