-
Notifications
You must be signed in to change notification settings - Fork 528
Advisory Improvement: Enhancements and Cleanup for GHSA Workflow (6866) #6888
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
Show all changes
48 commits
Select commit
Hold shift + click to select a range
aec00c2
Publish GHSA-qvpr-vq7h-28cr
advisory-database[bot] 515754e
Publish Advisories
advisory-database[bot] d7e63b2
Publish GHSA-9f3f-wv7r-qc8r
advisory-database[bot] e912a16
Publish GHSA-jp3q-wwp3-pwv9
advisory-database[bot] bc2ffab
Publish Advisories
advisory-database[bot] d14188d
Publish Advisories
advisory-database[bot] 8de3c83
Publish Advisories
advisory-database[bot] 72d2184
Publish GHSA-7ppg-37fh-vcr6
advisory-database[bot] fd8723f
Publish GHSA-pm44-x5x7-24c4
advisory-database[bot] 90f4467
Advisory Database Sync
advisory-database[bot] 7678023
Publish GHSA-qvhc-9v3j-5rfw
advisory-database[bot] b0da1d5
Publish GHSA-6426-9fv3-65x8
advisory-database[bot] acfcbcd
Publish Advisories
advisory-database[bot] 66a9e76
Publish GHSA-wv3h-x6c4-r867
advisory-database[bot] 111fcc8
Publish GHSA-hcvw-475w-8g7p
advisory-database[bot] b4e7ce4
Publish Advisories
advisory-database[bot] d4f4331
Publish Advisories
advisory-database[bot] 973ada4
Publish Advisories
advisory-database[bot] 67d3472
Publish GHSA-cgmm-x5ww-q5cr
advisory-database[bot] f9ac8a9
Advisory Database Sync
advisory-database[bot] bc3fdd2
Publish GHSA-37gf-gmxv-74wv
advisory-database[bot] 285b9b3
Publish GHSA-g78x-7vwx-9f58
advisory-database[bot] 1641304
Publish GHSA-699m-4v95-rmpm
advisory-database[bot] 54b43c1
Publish GHSA-fm6w-rrp3-2x4w
advisory-database[bot] 6076ced
Publish GHSA-78wq-6gcv-w28r
advisory-database[bot] 5127ee6
Publish Advisories
advisory-database[bot] 6e6e4b9
Publish GHSA-p5wr-5p37-2wm6
advisory-database[bot] b4cf7a0
Publish Advisories
advisory-database[bot] fc4eda9
Advisory Database Sync
advisory-database[bot] b7ec4ee
Publish Advisories
advisory-database[bot] 99426e3
Publish Advisories
advisory-database[bot] 3244613
Advisory Database Sync
advisory-database[bot] 2a4bb68
Publish Advisories
advisory-database[bot] e5296e2
Publish Advisories
advisory-database[bot] fb52933
Publish Advisories
advisory-database[bot] 9580c22
Publish Advisories
advisory-database[bot] 064f966
Publish Advisories
advisory-database[bot] d0a5254
Publish Advisories
advisory-database[bot] 8b7564a
Publish Advisories
advisory-database[bot] 3e1bb70
Publish Advisories
advisory-database[bot] aa91897
Publish Advisories
advisory-database[bot] eb17559
Publish Advisories
advisory-database[bot] 9a40eb1
Advisory Database Sync
advisory-database[bot] 41d956f
Publish Advisories
advisory-database[bot] e1df577
Publish Advisories
advisory-database[bot] f0d3f11
Publish Advisories
advisory-database[bot] 2d2b81c
Publish Advisories
advisory-database[bot] f981753
Publish Advisories
advisory-database[bot] File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
11 changes: 5 additions & 6 deletions
11
advisories/github-reviewed/2025/03/GHSA-3jxr-23ph-c89g/GHSA-3jxr-23ph-c89g.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
66 changes: 66 additions & 0 deletions
66
advisories/github-reviewed/2026/02/GHSA-27jp-wm6q-gp25/GHSA-27jp-wm6q-gp25.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,66 @@ | ||
| { | ||
| "schema_version": "1.4.0", | ||
| "id": "GHSA-27jp-wm6q-gp25", | ||
| "modified": "2026-02-13T16:16:11Z", | ||
| "published": "2026-02-13T16:16:11Z", | ||
| "aliases": [], | ||
| "summary": "sqlparse: formatting list of tuples leads to denial of service", | ||
| "details": "### Summary\nThe below gist hangs while attempting to format a long list of tuples.\n\nThis was found while [drafting a regression test for Dja\nngo 5.2's composite primary key feature](https://code.djangoproject.com/ticket/36416#comment:3), which allows querying composite fields with tuples.\n\n###", | ||
| "severity": [ | ||
| { | ||
| "type": "CVSS_V4", | ||
| "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" | ||
| } | ||
| ], | ||
| "affected": [ | ||
| { | ||
| "package": { | ||
| "ecosystem": "PyPI", | ||
| "name": "sqlparse" | ||
| }, | ||
| "ranges": [ | ||
| { | ||
| "type": "ECOSYSTEM", | ||
| "events": [ | ||
| { | ||
| "introduced": "0" | ||
| }, | ||
| { | ||
| "fixed": "0.5.4" | ||
| } | ||
| ] | ||
| } | ||
| ], | ||
| "database_specific": { | ||
| "last_known_affected_version_range": "<= 0.5.3" | ||
| } | ||
| } | ||
| ], | ||
| "references": [ | ||
| { | ||
| "type": "WEB", | ||
| "url": "https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-27jp-wm6q-gp25" | ||
| }, | ||
| { | ||
| "type": "WEB", | ||
| "url": "https://github.com/andialbrecht/sqlparse/commit/40ed3aa958657fa4a82055927fa9de70ab903360" | ||
| }, | ||
| { | ||
| "type": "PACKAGE", | ||
| "url": "https://github.com/andialbrecht/sqlparse" | ||
| }, | ||
| { | ||
| "type": "WEB", | ||
| "url": "https://github.com/andialbrecht/sqlparse/releases/tag/0.5.4" | ||
| } | ||
| ], | ||
| "database_specific": { | ||
| "cwe_ids": [ | ||
| "CWE-770" | ||
| ], | ||
| "severity": "MODERATE", | ||
| "github_reviewed": true, | ||
| "github_reviewed_at": "2026-02-13T16:16:11Z", | ||
| "nvd_published_at": null | ||
| } | ||
| } |
64 changes: 64 additions & 0 deletions
64
advisories/github-reviewed/2026/02/GHSA-2xf7-hmf6-p64j/GHSA-2xf7-hmf6-p64j.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,64 @@ | ||
| { | ||
| "schema_version": "1.4.0", | ||
| "id": "GHSA-2xf7-hmf6-p64j", | ||
| "modified": "2026-02-13T20:55:54Z", | ||
| "published": "2026-02-13T12:31:21Z", | ||
| "aliases": [ | ||
| "CVE-2026-20796" | ||
| ], | ||
| "summary": "Mattermost doesn't properly validate channel membership at the time of data retrieval", | ||
| "details": "Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID: MMSA-2025-00549", | ||
| "severity": [ | ||
| { | ||
| "type": "CVSS_V3", | ||
| "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" | ||
| } | ||
| ], | ||
| "affected": [ | ||
| { | ||
| "package": { | ||
| "ecosystem": "Go", | ||
| "name": "github.com/mattermost/mattermost-server" | ||
| }, | ||
| "ranges": [ | ||
| { | ||
| "type": "ECOSYSTEM", | ||
| "events": [ | ||
| { | ||
| "introduced": "10.11.0" | ||
| }, | ||
| { | ||
| "fixed": "10.11.10" | ||
| } | ||
| ] | ||
| } | ||
| ], | ||
| "database_specific": { | ||
| "last_known_affected_version_range": "<= 10.11.9" | ||
| } | ||
| } | ||
| ], | ||
| "references": [ | ||
| { | ||
| "type": "ADVISORY", | ||
| "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20796" | ||
| }, | ||
| { | ||
| "type": "PACKAGE", | ||
| "url": "https://github.com/mattermost/mattermost" | ||
| }, | ||
| { | ||
| "type": "WEB", | ||
| "url": "https://mattermost.com/security-updates" | ||
| } | ||
| ], | ||
| "database_specific": { | ||
| "cwe_ids": [ | ||
| "CWE-367" | ||
| ], | ||
| "severity": "LOW", | ||
| "github_reviewed": true, | ||
| "github_reviewed_at": "2026-02-13T20:55:54Z", | ||
| "nvd_published_at": "2026-02-13T11:16:10Z" | ||
| } | ||
| } |
2 changes: 1 addition & 1 deletion
2
advisories/github-reviewed/2026/02/GHSA-33mh-2634-fwr2/GHSA-33mh-2634-fwr2.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"modified": "2026-02-07T00:31:34Z",