Skip to content

Conversation

Humni
Copy link

@Humni Humni commented Aug 19, 2025

Updates

  • Affected products

Comments
patched version not tagged correctly

@Copilot Copilot AI review requested due to automatic review settings August 19, 2025 23:34
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates a security advisory for sweetalert2 to correctly specify the patched version. The change addresses an issue where the patched version was not tagged correctly in the vulnerability database.

  • Updates the modified timestamp to reflect the correction
  • Adds explicit "fixed" version information to properly indicate version 11.0.0 resolves the vulnerability
  • Removes the less precise "last_known_affected_version_range" field in favor of explicit version ranges

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@@ -19,13 +19,13 @@
"events": [
{
"introduced": "10.16.10"
},
Copy link
Preview

Copilot AI Aug 19, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nitpick] The trailing comma after the 'introduced' object creates an inconsistent JSON structure. Consider removing the comma on line 22 to maintain clean JSON formatting.

Copilot uses AI. Check for mistakes.

@github-actions github-actions bot changed the base branch from main to Humni/advisory-improvement-6031 August 19, 2025 23:35
@yhidad31
Copy link

Hi @Humni, your proposed fixed version does not address the hidden-functionality vulnerability identified in this GHSA, therefore we are not merging this contribution. We have updated the advisory with the correct patched version.

@yhidad31 yhidad31 closed this Aug 25, 2025
@github-actions github-actions bot deleted the Humni-GHSA-457r-cqc8-9vj9 branch August 25, 2025 17:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants