[GHSA-gj8w-mvpf-x27x] pnpm: Repository-controlled configDependencies can select a pacquet native install engine#8176
Conversation
|
Hi there @zkochan! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
Pull request overview
Updates a GitHub-reviewed advisory entry for GHSA-gj8w-mvpf-x27x (pnpm) to correct the recorded patched version information so downstream consumers get an accurate affected range.
Changes:
- Corrected the
affected[].ranges[].events[].fixedversion for the pre-11 release line to10.34.2. - Removed the now-redundant per-
affecteddatabase_specific.last_known_affected_version_rangeblock after updating the structured range data. - Bumped the advisory
modifiedtimestamp accordingly.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Updates
Comments
address incorrect patch version