Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Request to review GHSA-46qc-4j94-54hf and add patched versions

Abierto
#9,478 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
52/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Área
security

Línea de trabajo

Comienza con GHSA-46qc-4j94-54hf, el historial de versiones de @bananacool467/ui-tools y la documentación de seguridad del repositorio. Compara las correcciones documentadas en 0.1.9-beta, 0.2.0-beta y 0.2.1-beta con el rango afectado del aviso, y verifica si 1.0.0 forma parte de él. Se considera terminado cuando el aviso registra correctamente los rangos de versiones afectadas y corregidas.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

I am requesting a review of GHSA-46qc-4j94-54hf for @bananacool467/ui-tools.

The advisory currently lists:

  • Affected versions: 0.1.0-beta through 0.1.7-beta
  • Patched versions: None

The historical issue was an unauthenticated WebSocket terminal endpoint. This functionality was intentional, but authentication and security controls were missing from the early implementation.

The package was subsequently updated to address the issue:

  • 0.1.9-beta — authentication was added before the WebSocket upgrade / PTY creation.
  • 0.2.0-beta — additional security restrictions and hardening were added, including localhost defaults, origin restrictions, session ownership, connection/message/lifetime limits, environment restrictions, and configurable startup behavior.
  • 0.2.1-beta — credential verification and additional execution/sandbox controls were added.

I am therefore requesting that the advisory be reviewed to determine whether these releases should be represented as patched/remediated versions rather than showing “Patched versions: None.”

I am not requesting that the historical security issue or affected versions be removed.

I am requesting that the advisory accurately represent the subsequent security fixes and release history.

There is also a separate version-data issue worth reviewing: the advisory itself lists only the eight 0.1.x-beta versions above, while some third-party security aggregators currently display 1.0.0 as affected. 1.0.0 is not listed in this GHSA.

Relevant evidence includes the package's release history and the corresponding security documentation in the repository.

Please review the advisory and determine the appropriate corrected affected/patched version ranges.

Lenguaje dominante
Sin datos de lenguaje
Estrellas
2.5k
Forks
772
Merge medio
3 d 15 h
PR fusionados (30 d)
46

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de github/advisory-database

Todos los issues de github/advisory-database

Issues similares

Más issues de Security

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.