Skip to content

Conversation

G-Rath
Copy link

@G-Rath G-Rath commented Aug 10, 2025

Updates

  • Affected products

Comments
Added lodash-rails to list of impacted packages

@Copilot Copilot AI review requested due to automatic review settings August 10, 2025 19:19
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates a GitHub Security Advisory (GHSA-35jh-r3h4-6jhm) for a command injection vulnerability in lodash to include an additional affected package. The update adds lodash-rails to the list of impacted RubyGems packages and updates the modification timestamp.

  • Added lodash-rails RubyGems package to the affected products list
  • Updated the modification timestamp to reflect the change

"introduced": "0"
},
{
"fixed": "4.17.21"
Copy link
Preview

Copilot AI Aug 10, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fixed version '4.17.21' appears to be a JavaScript npm version for lodash, but this is being applied to the RubyGems package 'lodash-rails'. RubyGems packages typically have different versioning schemes than their JavaScript counterparts. Please verify that version 4.17.21 is a valid and correct version for the lodash-rails RubyGems package.

Suggested change
"fixed": "4.17.21"

Copilot uses AI. Check for mistakes.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is the correct version - the gems versioning matches the version of lodash that it provides (at least in the 4.x line)

@github-actions github-actions bot changed the base branch from main to G-Rath/advisory-improvement-5977 August 10, 2025 19:20
@advisory-database advisory-database bot merged commit 6c3d5fa into G-Rath/advisory-improvement-5977 Aug 11, 2025
4 checks passed
@advisory-database
Copy link
Contributor

Hi @G-Rath! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the G-Rath-GHSA-35jh-r3h4-6jhm branch August 11, 2025 14:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant