From ff3a115b47faa5c3fd236b774b962174e2f75837 Mon Sep 17 00:00:00 2001 From: Phil Date: Sun, 10 Dec 2023 08:45:41 -0800 Subject: [PATCH] Improve GHSA-vfp6-jrw2-99g9 --- .../GHSA-vfp6-jrw2-99g9/GHSA-vfp6-jrw2-99g9.json | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2023/11/GHSA-vfp6-jrw2-99g9/GHSA-vfp6-jrw2-99g9.json b/advisories/github-reviewed/2023/11/GHSA-vfp6-jrw2-99g9/GHSA-vfp6-jrw2-99g9.json index 94582f0439069..41c43b45c732e 100644 --- a/advisories/github-reviewed/2023/11/GHSA-vfp6-jrw2-99g9/GHSA-vfp6-jrw2-99g9.json +++ b/advisories/github-reviewed/2023/11/GHSA-vfp6-jrw2-99g9/GHSA-vfp6-jrw2-99g9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vfp6-jrw2-99g9", - "modified": "2023-11-08T15:02:51Z", + "modified": "2023-11-14T21:38:50Z", "published": "2023-11-08T15:02:51Z", "aliases": [ "CVE-2023-46737" @@ -18,7 +18,7 @@ { "package": { "ecosystem": "Go", - "name": "github.com/sigstore/cosign" + "name": "github.com/sigstore/cosign/v2" }, "ranges": [ { @@ -28,7 +28,7 @@ "introduced": "0" }, { - "last_affected": "1.13.1" + "fixed": "2.2.1" } ] } @@ -37,7 +37,7 @@ { "package": { "ecosystem": "Go", - "name": "github.com/sigstore/cosign/v2" + "name": "github.com/sigstore/cosign" }, "ranges": [ { @@ -47,11 +47,14 @@ "introduced": "0" }, { - "fixed": "2.2.1" + "fixed": "v1.13.2" } ] } - ] + ], + "database_specific": { + "last_known_affected_version_range": "<= 1.13.1" + } } ], "references": [