Skip to content

Conversation

@brophdawg11
Copy link

This is an update to the last_known_affected_version_range field for GHSA-cpj6-fhp6-mr6j.

We missed that the original advisory we received and subsequently published did not have a lower version bound, which is causing tools like npm audit to report false positives for the vulnerability on unaffected versions (v6 and below).

We have since updated the affected version via the Security UI in our repo, and it seems those updates have propagated to the introduced fields (here), but tools like npm audit are still reporting the vulnerability on versions below v7.

On a closer look we noticed the last_known_affected_version_range field still seemed to have the old version without the lower bound, so this updates that field hoping it will resolve the npm audit issues.

Copilot AI review requested due to automatic review settings April 25, 2025 15:15
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

Files not reviewed (1)

@github-actions github-actions bot changed the base branch from main to brophdawg11/advisory-improvement-5484 April 25, 2025 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant