Skip to content

Updated/renamed existing iodine advisory#1062

Merged
flavorjones merged 4 commits into
rubysec:masterfrom
jasnow:ghsa-syncbot-2026-05-23-09_44_44
May 23, 2026
Merged

Updated/renamed existing iodine advisory#1062
flavorjones merged 4 commits into
rubysec:masterfrom
jasnow:ghsa-syncbot-2026-05-23-09_44_44

Conversation

@jasnow
Copy link
Copy Markdown
Contributor

@jasnow jasnow commented May 23, 2026

Updated/renamed existing iodine advisory

Comment thread gems/iodine/CVE-2026-41146.yml Outdated
cve: 2026-41146
ghsa: 2x79-gwq3-vxxm
url: https://github.com/boazsegev/facil.io/security/advisories/GHSA-2x79-gwq3-vxxm
url: https://github.com/advisories/GHSA-2x79-gwq3-vxxm
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm still quite lost what belongs here. What is the priority for URL? If there's CVE, should be CVE priority?

Usually there is one of:

  • CVE
  • GHSA (generic page)
  • GHSA (project page)

Is there any proper order of choice here?

Copy link
Copy Markdown
Contributor Author

@jasnow jasnow May 23, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I changed the URL because the old one is for the wrong repo facil.io where the new old was GHSA-reviewed as a iodine gem advisory and it is less misleading at face value.

Regarding generic vs project page, there is usually the same except for rubies advisories and they are no project advisories but their are GHSA advisories.

Our (@postmodern) filename priority was CVE, GHSA, OSVDB. The "rake" linting checks for it.

PS. I will let you click "Resolve convention" from now on.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So any reason to not use CVE link here?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agree - the CVE link was created yesterday after my email - add chane.

Comment thread gems/iodine/CVE-2026-41146.yml Outdated
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2026-41146

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✂️

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added commit.

Comment thread gems/iodine/CVE-2026-41146.yml Outdated
Co-authored-by: Connor Shea <2977353+connorshea@users.noreply.github.com>
Copy link
Copy Markdown
Collaborator

@flavorjones flavorjones left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All comments seem to be resolved. Approving and merging.

@flavorjones flavorjones merged commit 7c8b10f into rubysec:master May 23, 2026
1 check passed
@jasnow jasnow deleted the ghsa-syncbot-2026-05-23-09_44_44 branch May 23, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants