Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

Problems with GHSA-2v4p-qf9q-27wj

Aberta
#9,772 1 comentário 0 reações 0 responsáveis Ver no GitHub

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
4/5
Tempo estimado
3-5 dias
Facilidade para iniciantes
38/100
Tipo de issue
Bug
Clareza
Razoavelmente clara
Status de atividade
Ativa
Stack de tecnologia
go
Domínio
databases, security

Direção de pesquisa

Start by reading GHSA-2v4p-qf9q-27wj and comparing its patched-version metadata with advisory-database PR #9608. Trace how the advisory database records and publishes the affected range, then verify that scanners no longer report grpc-go 1.84.0 as vulnerable; confirm whether any further maintainer action is required.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

The grpc-go team recently published a security advisory: https://github.com/advisories/GHSA-2v4p-qf9q-27wj

The fix for the above vulnerability was made to our master branch after we cut the branch for release 1.84.0. The advisory initially mentioned that the vulnerability affected versions <=1.83.1, because at that point the most recent release was 1.83.1. As part of publishing the advisory we also pushed out a couple of patch releases, 1.82.2 and 1.83.2 and marked them as the patched versions in the advisory.

After publishing the advisory, we cherry-picked the change into the 1.84.x branch and pushed out 1.84.0 release that contained the fix.

But scanning tools are listing 1.84.0 to be affected by this vulnerability and downstream users of grpc-go using 1.84.0 are showing up as vulnerable.

How do we go about fixing this?

Please let us know if there is something more needs to be done from our side.

Thanks

Linguagem predominante
Sem dados de linguagem
Estrelas
2.5k
Forks
772
Merge médio
4d 17h
PRs com merge (30d)
75

Guia de contribuição

Abrir o guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de github/advisory-database

Todas as issues de github/advisory-database

Issues semelhantes

Mais issues de Databases

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.