Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve references in RUSTSEC-2024-0359 #2202

Conversation

EliahKagan
Copy link
Contributor

This improves credit and adds a missing GHSA alias in RUSTSEC-2024-0359 (which is based on GitoxideLabs/gitoxide#1460 and originally added in #2027). See commit messages for details, including rationale.

cc @Byron @ssbr

In some cases it is easy to see who discovered and reported a bug,
but in the case of RUSTSEC-2024-0359 (GHSA-cx7h-h87r-jpgr) one
would have had to follow a link to the issue (or look at the
advisory-db commit history).

Furthermore, the text of the advisory here is directly based on
the text of that issue. So improving attribution seems worthwhile
in this case.

This adds brief explicit credit to @ssbr at the end of the body of
the advisory. This is modeled roughly after how credit was given in
RUSTSEC-2023-0064 (GHSA-rrjw-j4m2-mf34), another gitoxide advisory.

Because the GitHub Advisory Database entry GHSA-cx7h-h87r-jpgr for
RUSTSEC-2024-0359 is imported from here, I believe it will also
(eventually) be updated with this change, even without being edited
directly.

Although that database supports credit metadata, it seems currently
infeasible to add reporter or finder credit to an entry that is
imported from RUSTSEC rather than, e.g., from a repo-local GHSA
(github/advisory-database#4620). So
this is also in effect a workaround for that.
The main metadata change here is to add the missing global GHSA
alias (see GHSA-cx7h-h87r-jpgr).

While I'm at it, I've also updated the reference issue URL, since
the `gitoxide` repository is under `GitoixeLabs` now (moved from
`Byron`).
@Shnatsel Shnatsel merged commit cfd49ce into rustsec:main Jan 19, 2025
1 check passed
@EliahKagan EliahKagan deleted the gix-attributes-unsound-kstring-integration-next branch January 19, 2025 00:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants