Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-54xq-cgqr-rpm3] sharp vulnerability in libwebp dependency CVE-2023-4863 #5240

Closed

Conversation

Xyaren
Copy link

@Xyaren Xyaren commented Jan 30, 2025

Updates

  • Affected products

Comments
Patched version does not exist

@github
Copy link
Collaborator

github commented Jan 30, 2025

Hi there @lovell! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions github-actions bot changed the base branch from main to Xyaren/advisory-improvement-5240 January 30, 2025 15:25
@lovell
Copy link

lovell commented Jan 30, 2025

Patched version does not exist

Are you able to explain more about this comment given the existence of https://www.npmjs.com/package/sharp/v/0.32.6

In addition, my understanding of the OSV format is that fixed is rather important, and removing it could break automated tooling that depends upon it.

@darakian
Copy link
Contributor

+1
would love more of an explanation here

@Xyaren
Copy link
Author

Xyaren commented Jan 30, 2025

Sorry, misinterpreted an error in the dependabot pipeline. 😞
Apparently got confused between 0.32.6 and 0.33.6

@Xyaren Xyaren closed this Jan 30, 2025
@github-actions github-actions bot deleted the Xyaren-GHSA-54xq-cgqr-rpm3 branch January 30, 2025 20:04
@darakian
Copy link
Contributor

All good. Thanks for taking the time to act on something you thought was wrong :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants