{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":8154497,"defaultBranch":"master","name":"ruby-advisory-db","ownerLogin":"rubysec","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2013-02-12T07:10:30.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/3538974?v=4","public":true,"private":false,"isOrgOwned":true},"refInfo":{"name":"","listCacheKey":"v0:1711327649.0","currentOid":""},"activityList":{"items":[{"before":"2780bcd33ee26cc4577cbc5ec7c59a5be07b2fac","after":"5e77a68ffb3efbe1f4de93cf3ee2c7b74521cc62","ref":"refs/heads/master","pushedAt":"2024-09-18T18:41:17.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: 1 brand new advisory","shortMessageHtmlLink":"GHSA SYNC: 1 brand new advisory"}},{"before":"a49ad8b16072bb3ee3a5d9dd4ea68ceaae2bf9ad","after":"2780bcd33ee26cc4577cbc5ec7c59a5be07b2fac","ref":"refs/heads/master","pushedAt":"2024-09-17T18:43:27.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: 3 brand new advisories","shortMessageHtmlLink":"GHSA SYNC: 3 brand new advisories"}},{"before":"46096c9b5591c25b89f83a182bde875a62fe5387","after":"a49ad8b16072bb3ee3a5d9dd4ea68ceaae2bf9ad","ref":"refs/heads/master","pushedAt":"2024-09-14T18:24:07.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: 1 brand new advisory","shortMessageHtmlLink":"GHSA SYNC: 1 brand new advisory"}},{"before":"9a88f501a73e9d55c5142286dac075732d8febb0","after":"46096c9b5591c25b89f83a182bde875a62fe5387","ref":"refs/heads/master","pushedAt":"2024-09-13T07:24:51.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Add CVE-2024-45409 for ruby-saml and omniauth-saml","shortMessageHtmlLink":"Add CVE-2024-45409 for ruby-saml and omniauth-saml"}},{"before":"ec3b659a4ee3773539712f866bb2b32f2427be62","after":"9a88f501a73e9d55c5142286dac075732d8febb0","ref":"refs/heads/master","pushedAt":"2024-08-26T20:52:57.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Re-add `>= 7.2.0.beta2` to patched versions for CVE-2024-28103 / CVE-2024-32464.\n\n* While the original advisories do not mention 7.2.0.beta2 as being\n patched, the GHSA advisories do, however.\n * https://github.com/rails/rails/security/advisories/GHSA-fwhr-88qx-h9g7\n * https://github.com/rails/rails/security/advisories/GHSA-prjp-h48f-jgf6","shortMessageHtmlLink":"Re-add >= 7.2.0.beta2 to patched versions for CVE-2024-28103 / CVE-…"}},{"before":"35b6894b4476e5e1e1cee9c223eabee3a22e41fd","after":"ec3b659a4ee3773539712f866bb2b32f2427be62","ref":"refs/heads/master","pushedAt":"2024-08-26T17:34:38.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Fixed `~>` patched version ranges for CVE-2024-28103.","shortMessageHtmlLink":"Fixed ~> patched version ranges for CVE-2024-28103."}},{"before":"33907c16654555cb6089d8a41c6bd20ce8da2698","after":"35b6894b4476e5e1e1cee9c223eabee3a22e41fd","ref":"refs/heads/master","pushedAt":"2024-08-26T17:27:47.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Simplify the patched version ranges for CVE-2024-32464 and CVE-2024-28103.","shortMessageHtmlLink":"Simplify the patched version ranges for CVE-2024-32464 and CVE-2024-2…"}},{"before":"1f32ea5ffe106eca937948d1159ed2ad331244cd","after":"33907c16654555cb6089d8a41c6bd20ce8da2698","ref":"refs/heads/master","pushedAt":"2024-08-24T18:36:02.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GSHA SYNC: 1 brand new advisory","shortMessageHtmlLink":"GSHA SYNC: 1 brand new advisory"}},{"before":"3a4007eb274e3489c0c553a6da69e1590a65ef2e","after":"1f32ea5ffe106eca937948d1159ed2ad331244cd","ref":"refs/heads/master","pushedAt":"2024-08-24T00:18:16.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GSHA SYNC: 1 brand new advisory","shortMessageHtmlLink":"GSHA SYNC: 1 brand new advisory"}},{"before":"e38cfdd4a646821224272f3a4d404171d34dc9ce","after":"3a4007eb274e3489c0c553a6da69e1590a65ef2e","ref":"refs/heads/master","pushedAt":"2024-08-21T12:00:56.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: Added cvss_v3 field to 1 advisory","shortMessageHtmlLink":"GHSA SYNC: Added cvss_v3 field to 1 advisory"}},{"before":"b5e80a635bcc4d85d6e9f5b741510fb63a05150f","after":"e38cfdd4a646821224272f3a4d404171d34dc9ce","ref":"refs/heads/master","pushedAt":"2024-08-20T23:44:10.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GSHA SYNC: 1 brand new advisory (#802)\n\n---------\r\n\r\nCo-authored-by: Postmodern ","shortMessageHtmlLink":"GSHA SYNC: 1 brand new advisory (#802)"}},{"before":"c397acb102af20388447b6e5c3d1f78fb14f08c8","after":"b5e80a635bcc4d85d6e9f5b741510fb63a05150f","ref":"refs/heads/master","pushedAt":"2024-08-19T06:32:59.000Z","pushType":"push","commitsCount":3,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Lint the YAML syntax before linting the contents of the YAML files.","shortMessageHtmlLink":"Lint the YAML syntax before linting the contents of the YAML files."}},{"before":"3f2952b7fd694022225eb502be77a9b8b4b5676a","after":"c397acb102af20388447b6e5c3d1f78fb14f08c8","ref":"refs/heads/master","pushedAt":"2024-08-14T19:27:08.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GSHA SYNC: 2 brand new advisories","shortMessageHtmlLink":"GSHA SYNC: 2 brand new advisories"}},{"before":"446f84809ca2f370b7e2880065e066b7c4cb3465","after":"3f2952b7fd694022225eb502be77a9b8b4b5676a","ref":"refs/heads/master","pushedAt":"2024-08-04T00:03:05.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: 1 modified advisory; 1 brand new advisory","shortMessageHtmlLink":"GHSA SYNC: 1 modified advisory; 1 brand new advisory"}},{"before":"74cb95f7ca90abf9f93a1a1a1fb37c48229a285b","after":"446f84809ca2f370b7e2880065e066b7c4cb3465","ref":"refs/heads/master","pushedAt":"2024-08-03T02:22:01.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: 3 modified and 8 brand new advisories (#799)\n\n* Added `patched_versions` to `gems/bootstrap/CVE-2024-6531.yml`.\r\n According to the [CVE-2024-6531 blog post][1] the affected versions are\r\n `>= 4.0.0, <= 4.6.2`, and the [bootstrap gem] has versions after 4.6.2 which\r\n contain newer versions of the bootstrap JavaScript library.\r\n* Added `patched_versions` to `gems/bootstrap/CVE-2024-6484.yml`.\r\n According to the [CVE-2024-6484 blog post][2], the affected versions are\r\n `>= 2.0.0, <= 3.4.1`, but the [bootstrap gem] has versions after 3.4.1\r\n containing newer versions of the bootstrap JavaScript library.\r\n\r\n[1]: https://www.herodevs.com/vulnerability-directory/cve-2024-6531\r\n[2]: https://www.herodevs.com/vulnerability-directory/cve-2024-6484\r\n[bootstrap gem]: https://rubygems.org/gems/bootstrap/versions\r\n\r\n---------\r\n\r\nCo-authored-by: Postmodern ","shortMessageHtmlLink":"GHSA SYNC: 3 modified and 8 brand new advisories (#799)"}},{"before":"1b7ad859170a81f642a5da3c45e877ac5d3ecf6b","after":"74cb95f7ca90abf9f93a1a1a1fb37c48229a285b","ref":"refs/heads/master","pushedAt":"2024-08-01T16:48:57.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Added CVE-2024-41123 and CVE-2024-41946 for the rexml gem (#798)\n\n---------\r\n\r\nCo-authored-by: Postmodern ","shortMessageHtmlLink":"Added CVE-2024-41123 and CVE-2024-41946 for the rexml gem (#798)"}},{"before":"a3b9e1240633295a4c5582bbe353bf22ec595090","after":"1b7ad859170a81f642a5da3c45e877ac5d3ecf6b","ref":"refs/heads/master","pushedAt":"2024-07-30T20:14:58.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: 1 brand new advisory","shortMessageHtmlLink":"GHSA SYNC: 1 brand new advisory"}},{"before":"448d4a3b6961d22b47fcb072d9385e8bc1c7fb8d","after":"a3b9e1240633295a4c5582bbe353bf22ec595090","ref":"refs/heads/master","pushedAt":"2024-07-17T19:30:44.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC adds `ghsa` and `cvss_v3` fields to CVE-2024-39908 (#796)","shortMessageHtmlLink":"GHSA SYNC adds ghsa and cvss_v3 fields to CVE-2024-39908 (#796)"}},{"before":"58766d871b78e5277a80c24b51aff36f6e17e0e1","after":"448d4a3b6961d22b47fcb072d9385e8bc1c7fb8d","ref":"refs/heads/master","pushedAt":"2024-07-16T16:59:47.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Added CVE-2024-39908 for rexml gem (#795)","shortMessageHtmlLink":"Added CVE-2024-39908 for rexml gem (#795)"}},{"before":"577457f66c6cc2527ee50401287bbe1d2acbe07a","after":"58766d871b78e5277a80c24b51aff36f6e17e0e1","ref":"refs/heads/master","pushedAt":"2024-07-11T20:22:56.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: 3 brand new advisories (#794)","shortMessageHtmlLink":"GHSA SYNC: 3 brand new advisories (#794)"}},{"before":"ac6a3c13c3b73f751f8810faf57dad29bef5625f","after":"577457f66c6cc2527ee50401287bbe1d2acbe07a","ref":"refs/heads/master","pushedAt":"2024-07-09T17:03:54.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: Added brand new advisory (#793)","shortMessageHtmlLink":"GHSA SYNC: Added brand new advisory (#793)"}},{"before":"606271ddd6df5c22f95158b095671859d378110e","after":"ac6a3c13c3b73f751f8810faf57dad29bef5625f","ref":"refs/heads/master","pushedAt":"2024-07-06T20:07:51.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Added cvss_v3 field to advisory","shortMessageHtmlLink":"Added cvss_v3 field to advisory"}},{"before":"a8a8f82c36872f7336bc321a6a93a76ecf7b3dd8","after":"606271ddd6df5c22f95158b095671859d378110e","ref":"refs/heads/master","pushedAt":"2024-07-04T15:29:42.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: One brand new advisory (#791)\n\n* Removed the URL for GHSA-54rr-7fvw-6x8f / CVE-2024-26146 which is unrelated.\r\n\r\n---------\r\n\r\nCo-authored-by: Postmodern ","shortMessageHtmlLink":"GHSA SYNC: One brand new advisory (#791)"}},{"before":"b1bb1f74eccd3b6eb98ca11414b5804e50ccb3b6","after":"a8a8f82c36872f7336bc321a6a93a76ecf7b3dd8","ref":"refs/heads/master","pushedAt":"2024-06-25T03:04:27.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Added Rspec check for PoC sections inside description field","shortMessageHtmlLink":"Added Rspec check for PoC sections inside description field"}},{"before":"0049582946f46532bcb5ea8b2b0e6322a2032886","after":"b1bb1f74eccd3b6eb98ca11414b5804e50ccb3b6","ref":"refs/heads/master","pushedAt":"2024-06-21T20:41:02.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Added rspec check for embedded double newlines (closes #788)\n\n* Added rspec check for embedded double newlines.\r\n* Fixed two other advisories with embedded double newlines.\r\n\r\n---------\r\n\r\nCo-authored-by: Postmodern ","shortMessageHtmlLink":"Added rspec check for embedded double newlines (closes #788)"}},{"before":"3f8ac23071db507f3ca3c57d1835dbf8c60265dd","after":"0049582946f46532bcb5ea8b2b0e6322a2032886","ref":"refs/heads/master","pushedAt":"2024-06-05T19:44:45.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: 2 brand new advisories","shortMessageHtmlLink":"GHSA SYNC: 2 brand new advisories"}},{"before":"ee0172a8201182d5f9ddef6fd673944aad9205bb","after":"3f8ac23071db507f3ca3c57d1835dbf8c60265dd","ref":"refs/heads/master","pushedAt":"2024-06-03T13:37:35.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Correct affected versions for CVE-2024-34341\n\nAs documented officially at https://discuss.rubyonrails.org/t/xss-vulnerabilities-in-trix-editor/85803\n\nSigned-off-by: Chad Wilson ","shortMessageHtmlLink":"Correct affected versions for CVE-2024-34341"}},{"before":"0a89cf8a3539f5d74ee2814b5665c2b51e4d24ed","after":"ee0172a8201182d5f9ddef6fd673944aad9205bb","ref":"refs/heads/master","pushedAt":"2024-06-03T12:35:24.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"GHSA SYNC: 1 brand new advisory","shortMessageHtmlLink":"GHSA SYNC: 1 brand new advisory"}},{"before":"0ef3d2dfe4601f7f5e241370d6cd84738bae4a12","after":"0a89cf8a3539f5d74ee2814b5665c2b51e4d24ed","ref":"refs/heads/master","pushedAt":"2024-06-03T05:00:21.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"Add CVE-2024-34341 for actiontext (#784)","shortMessageHtmlLink":"Add CVE-2024-34341 for actiontext (#784)"}},{"before":"0d915671f08036591d4ddf6de41e3eb90c836352","after":"0ef3d2dfe4601f7f5e241370d6cd84738bae4a12","ref":"refs/heads/master","pushedAt":"2024-05-30T02:49:37.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"postmodern","name":"Postmodern","path":"/postmodern","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/12671?s=80&v=4"},"commit":{"message":"[lint] Remove trailing whitespace.","shortMessageHtmlLink":"[lint] Remove trailing whitespace."}}],"hasNextPage":true,"hasPreviousPage":false,"activityType":"all","actor":null,"timePeriod":"all","sort":"DESC","perPage":30,"cursor":"djE6ks8AAAAEugyXQAA","startCursor":null,"endCursor":null}},"title":"Activity · rubysec/ruby-advisory-db"}