Skip to content

[GHSA-9vcr-p3rj-q5q6] sigstore-go: align described fixed version with the recorded range (fixed in v1.2.0, not v1.1.5) - #9206

Open
pacocartones wants to merge 1 commit into
github:pacocartones/advisory-improvement-9206from
pacocartones:fix/ghsa-9vcr-p3rj-q5q6-prose
Open

[GHSA-9vcr-p3rj-q5q6] sigstore-go: align described fixed version with the recorded range (fixed in v1.2.0, not v1.1.5)#9206
pacocartones wants to merge 1 commit into
github:pacocartones/advisory-improvement-9206from
pacocartones:fix/ghsa-9vcr-p3rj-q5q6-prose

Conversation

@pacocartones

@pacocartones pacocartones commented Aug 25, 2026

Copy link
Copy Markdown

Summary

Correct the patched version in the advisory prose from v1.1.5 to v1.2.0.

The structured affected range already identifies 1.2.0 as the first fixed version, and the advisory references the upstream v1.2.0 release. No v1.1.5 tag exists in sigstore-go.

Scope

This changes only the prose in GHSA-9vcr-p3rj-q5q6; ranges and metadata are unchanged.

Validation

  • JSON parses successfully with jq empty.
  • Diff is exactly one replacement in the advisory details.
  • git diff --check passes.

@github-actions
github-actions Bot changed the base branch from main to pacocartones/advisory-improvement-9206 August 25, 2026 17:35
@pacocartones pacocartones changed the title Fix patched version in GHSA-9vcr-p3rj-q5q6 [GHSA-9vcr-p3rj-q5q6] sigstore-go: align described fixed version with the recorded range (fixed in v1.2.0, not v1.1.5) Aug 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant