Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-r23g-3qw4-gfh2] RedCloth Cross-site Scripting vulnerability #2310

Closed

Conversation

jasnow
Copy link

@jasnow jasnow commented May 25, 2023

Updates

  • Affected products

Comments
Fix package name's case (s/redcloth/RedCloth). To verify change, see https://rubygems.org/gems/RedCloth web site.

@github-actions github-actions bot changed the base branch from main to jasnow/advisory-improvement-2310 May 25, 2023 19:20
@shelbyc
Copy link
Contributor

shelbyc commented May 26, 2023

Good morning @jasnow! I checked the JSON file for GHSA-r23g-3qw4-gfh2, and RedCloth already has the proper capitalization. This is an instance of a bug that prevents RubyGems package names from appearing as anything other than all lowercase on the github.com/advisories pages.

There's an ongoing issue related to Rubygems packages appearing as all lowercase on advisory pages regardless of whether any capital letters are used in package names in the JSON files. You can read more about it here: #52 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants