Skip to content

Update CommonMark released-fix guidance for GHSA-3q6v-r5mr-hxv8 - #10134

Open
nazeeh111 wants to merge 1 commit into
github:nazeeh111/advisory-improvement-10134from
nazeeh111:commonmark-ghsa-3q6v-r5mr-hxv8-released-fix-guidance
Open

nazeeh111 wants to merge 1 commit into
github:nazeeh111/advisory-improvement-10134from
nazeeh111:commonmark-ghsa-3q6v-r5mr-hxv8-released-fix-guidance

Conversation

@nazeeh111

Copy link
Copy Markdown

Update CommonMark released-fix guidance for GHSA-3q6v-r5mr-hxv8

The record already lists 2.10.2 as fixed, but its narrative still says "not fixed" and "No published release" and presents a suggested algorithm instead of the released fix. This updates the fix guidance and marks the earlier investigation's release-status observations as historical. Affected ranges, severity, references, reporter and the original vulnerability evidence remain unchanged.

The maintainer's 2.10.2 security release explicitly names this advisory. Its annotated tag resolves to 692e90b9, which contains the named fix commit. The released parser checks the current delimiter row before inspecting accumulated paragraph content and matches header/delimiter cell counts to GFM.

Validation: original and proposed JSON pass the OSV schema; seven exact narrative replacements preserve every other field. This is public source inspection, not local exploit or performance replication. Prepared with Codex assistance; no original discovery claimed.

@github-actions
github-actions Bot changed the base branch from main to nazeeh111/advisory-improvement-10134 October 3, 2026 16:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant