Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ignore bogus nette/database GHSA/CVE #759

Merged
merged 1 commit into from
Dec 17, 2024
Merged

Conversation

spaze
Copy link
Contributor

@spaze spaze commented Dec 17, 2024

Ignore GHSA-f626-677r-j5vq which is, per nette/database#314, a documented and intended feature. The PoC repo and the article from the GHSA are now gone and the CVE itself (CVE-2024-55586) is disputed.

Ignore GHSA-f626-677r-j5vq which is, per nette/database#314, a documented and intended feature. The PoC repo and the article from the GHSA are now gone and the CVE itself (CVE-2024-55586) is disputed.
Copy link
Member

@Ocramius Ocramius left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @spaze!

@Ocramius
Copy link
Member

hmm, something fishy going on with laminas/laminas-ci-matrix-action#318

@Ocramius Ocramius merged commit 7302998 into Roave:latest Dec 17, 2024
7 of 8 checks passed
@Ocramius
Copy link
Member

BTW, please also cooperate with the upstream advisories repo to get this adjusted

@spaze spaze deleted the patch-1 branch December 17, 2024 11:38
@spaze
Copy link
Contributor Author

spaze commented Dec 17, 2024

Thanks @Ocramius! GitHub advisory repo has an open PR by @calvera github/advisory-database#5074 and they're waiting for the CVE to be rejected (next stage after disputed I guess). I'll update this PR (or create a new one) if anything interesting happens.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants