Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Two published repository advisories not ingested into the Advisory Database after eight days

Open
#9,270 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Active
Tech stack
php, python

Research direction

No files, tests, or code entry points are named. Start by checking the ingestion status for GHSA-8c32-52rh-j928 and GHSA-r4f8-3xc4-c8vw, along with their repository publication and package metadata; done means both advisories are present in the Advisory Database and OSV.

Written by the indexing model from the issue text.

Description

Hi — flagging two repository-level advisories that were published on 2026-08-22 and, eight days later, still return 404 at github.com/advisories/ and are absent from OSV:

  • GHSA-8c32-52rh-j928 — netcarver/textile (Composer), published by the maintainer, fixed in 4.1.5
  • GHSA-r4f8-3xc4-c8vw — cloudpathlib (PyPI), published by the maintainer, fixed in 0.25.0

Both are published on their repositories and both have a released fix, so downstream users should be getting a signal. Right now composer audit/Packagist shows nothing for netcarver/textile, and Dependabot shows nothing for cloudpathlib <= 0.24.0.

For comparison, two other advisories I reported were reviewed and ingested quickly — GHSA-r3hx-x5rh-p9vv the same day it published, and GHSA-f2ff-p2ww-7p4p within about two days — so these two look like they may have been missed rather than deliberately held.

Is there anything the maintainers or I need to do on our side, or is this just review backlog? Happy to wait if it's the latter; I mainly wanted to make sure they hadn't fallen out of the queue.

Thanks for maintaining this.

Dominant language
No language data
Stars
2.5k
Forks
772
Avg merge
3d 18h
Merged PRs (30d)
48

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/advisory-database

All issues in github/advisory-database

Similar issues

More Databases issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.