Skip to content

Conversation

@Cycloctane
Copy link

Updates

  • Affected products
  • Description
  • References
  • Source code location
  • Summary

Comments
#6380 (comment)
#6380 (comment)

Copilot AI review requested due to automatic review settings November 17, 2025 09:59
@github-actions github-actions bot changed the base branch from main to Cycloctane/advisory-improvement-6424 November 17, 2025 10:01
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates security advisory GHSA-2qfp-q593-8484 to refocus it from Brotli to Scrapy as the primary affected package. The advisory describes a denial of service vulnerability in Scrapy's brotli decompression implementation.

  • Refocused the advisory from Brotli to Scrapy as the primary affected package
  • Updated version ranges to reflect that Scrapy 2.13.4 includes a fix
  • Reorganized and cleaned up references to focus on Scrapy-specific resources

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@advisory-database advisory-database bot merged commit 116c3fa into Cycloctane/advisory-improvement-6424 Nov 17, 2025
10 checks passed
@advisory-database
Copy link
Contributor

Hi @Cycloctane! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the Cycloctane-GHSA-2qfp-q593-8484 branch November 17, 2025 15:50
@shelbyc
Copy link
Contributor

shelbyc commented Nov 17, 2025

Hi @Cycloctane, thanks for the update on scrapy/scrapy#7134 and the release of Scrapy 2.13.4. The changes to GHSA-2qfp-q593-8484 should be visible now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants