Skip to content

[GHSA-9hxg-w7qf-hh93] Use Go pseudo-version for fixed version#7477

Open
cookesan wants to merge 1 commit intogithub:cookesan/advisory-improvement-7477from
cookesan:codex/ghsa-9hxg-go-pseudoversion
Open

[GHSA-9hxg-w7qf-hh93] Use Go pseudo-version for fixed version#7477
cookesan wants to merge 1 commit intogithub:cookesan/advisory-improvement-7477from
cookesan:codex/ghsa-9hxg-go-pseudoversion

Conversation

@cookesan
Copy link
Copy Markdown

This updates the fixed version for gogs.io/gogs in GHSA-9hxg-w7qf-hh93 from the Gogs application version 0.11.82.1218 to the Go module pseudo-version for the referenced fix commit.

Evidence:

  • The advisory references gogs/gogs@ff93d9dbda5cebe90d86e4b7dfb2c6b8642970ce.
  • That commit is pkg/tool: improve SanitizePath (#5558) and updates APP_VER to 0.11.82.1218.
  • go list -m -json gogs.io/gogs@ff93d9dbda5cebe90d86e4b7dfb2c6b8642970ce resolves it as v0.11.80-0.20181218063808-ff93d9dbda5c.
  • The Advisory Database convention for Go ranges omits the leading v, so this PR records 0.11.80-0.20181218063808-ff93d9dbda5c.

This addresses one item from #7355. I kept the PR to one advisory per the contribution guidelines.

@github-actions github-actions Bot changed the base branch from main to cookesan/advisory-improvement-7477 April 21, 2026 18:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant