-
Notifications
You must be signed in to change notification settings - Fork 423
Pypi patch/affected version fixes and remove patched version from GHSA-22fp-mf44-f2mq #5639
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
I'm not sure why some PRs don't just show updated patched and vulnerable version ranges: feel free to just update these yourself if desired. |
Hi @rhdesmond, I agree that there isn't a great way to talk about fixed versions of |
Thanks Shelby, I agree that it's an odd scenario. My recommendation is using the package versions from the Pypi registry as the source of truth as noted in the docs; until a release is on Pypi that contains the patched fix, there is no fixed version. Otherwise we may have to account for N different registries (https://xkcd.com/927/) and data quality issues. The owners can release a new version on Pypi if they want the fixed code publicly reported. Perhaps the patched information could be noted in a text section? Or if you do want to report the Thanks for your consideration! |
After taking some time to think about it, I removed Do you want to receive a credit as an |
It would be an honor (if it's not too much work)! Thank you 🙏 |
@rhdesmond Your credit should appear on GHSA-22fp-mf44-f2mq now. Thanks again for the great conversation and have a good week! |
I tried to make a pull request to GHSA-22fp-mf44-f2mq using the "suggest an improvement" button, but there was an error page when trying to submit the pull request.
I removed the fixed version with the reason "Fixed version is non-existent: https://pypi.org/project/youtube_dl/#history / https://github.com/ytdl-org/youtube-dl/releases". Could someone make this simple change please?
The text was updated successfully, but these errors were encountered: