Skip to content

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Jan 16, 2026

GHSA SYNC: 1 brand new advisory

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I cannot verify that versions >= 0.5.3 are actually patched. The GHSA entry lists no versions, the NVD entry lists >= 0.5, the GitLab advisory lists >= 0.5.1 instead of >= 0.5.3. Will require manual verification.

@jasnow
Copy link
Contributor Author

jasnow commented Jan 16, 2026

Check the GitHub URLs listed in advisory.

Also see no release 0.5.1 list in https://github.com/fetlife/rollout-ui/releases

Boldfaced "feature" in text for CVE-2023-25309 description
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants