Skip to content

Conversation

@aiob3
Copy link

@aiob3 aiob3 commented Nov 14, 2025

Updates

  • CVSS v3
  • Severity

Comments
need to fix into actions

Copilot AI review requested due to automatic review settings November 14, 2025 18:38
@github
Copy link
Collaborator

github commented Nov 14, 2025

Hi there @puzrin! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions github-actions bot changed the base branch from main to aiob3/advisory-improvement-6418 November 14, 2025 18:39
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the security advisory for js-yaml prototype pollution vulnerability (GHSA-mh29-5h37-fv8m) by revising the CVSS v3.1 score and corresponding severity rating to reflect a lower risk assessment.

  • Changed CVSS vector from Network attack (AV:N) with no privileges required (PR:N) to Local attack (AV:L) with low privileges required (PR:L)
  • Updated severity classification from MODERATE to LOW, consistent with the reduced CVSS score (5.3 → 3.3)
  • Incremented the modification timestamp by one second

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@helixplant
Copy link

Thank you for your submission. After careful review, we've determined that the proposed severity change does not accurately reflect the nature of this vulnerability, and we will not be accepting this score.

@helixplant helixplant closed this Nov 14, 2025
@github-actions github-actions bot deleted the aiob3-GHSA-mh29-5h37-fv8m branch November 14, 2025 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants