Skip to content

[GHSA-9hxg-w7qf-hh93] Use Go pseudo-version for fixed version#7477

Merged
advisory-database[bot] merged 1 commit into
github:cookesan/advisory-improvement-7477from
cookesan:codex/ghsa-9hxg-go-pseudoversion
May 14, 2026
Merged

[GHSA-9hxg-w7qf-hh93] Use Go pseudo-version for fixed version#7477
advisory-database[bot] merged 1 commit into
github:cookesan/advisory-improvement-7477from
cookesan:codex/ghsa-9hxg-go-pseudoversion

Conversation

@cookesan
Copy link
Copy Markdown

This updates the fixed version for gogs.io/gogs in GHSA-9hxg-w7qf-hh93 from the Gogs application version 0.11.82.1218 to the Go module pseudo-version for the referenced fix commit.

Evidence:

  • The advisory references gogs/gogs@ff93d9dbda5cebe90d86e4b7dfb2c6b8642970ce.
  • That commit is pkg/tool: improve SanitizePath (#5558) and updates APP_VER to 0.11.82.1218.
  • go list -m -json gogs.io/gogs@ff93d9dbda5cebe90d86e4b7dfb2c6b8642970ce resolves it as v0.11.80-0.20181218063808-ff93d9dbda5c.
  • The Advisory Database convention for Go ranges omits the leading v, so this PR records 0.11.80-0.20181218063808-ff93d9dbda5c.

This addresses one item from #7355. I kept the PR to one advisory per the contribution guidelines.

@github-actions github-actions Bot changed the base branch from main to cookesan/advisory-improvement-7477 April 21, 2026 18:39
@cookesan
Copy link
Copy Markdown
Author

Friendly follow-up on this advisory improvement. The intent here is only to record the fixed version for gogs.io/gogs as the Go module pseudo-version for ff93d9dbda5c, since that is the identifier dependency tooling resolves for the referenced fix commit. If that matches current advisory-database conventions, this should be ready for review; if not, I'm happy to adjust it.

@advisory-database advisory-database Bot merged commit 6014f62 into github:cookesan/advisory-improvement-7477 May 14, 2026
2 checks passed
@advisory-database
Copy link
Copy Markdown
Contributor

Hi @cookesan! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant