Skip to content

Conversation

@medikoo
Copy link

@medikoo medikoo commented Oct 31, 2023

Fix issue where security vulnerability is incorrectly applied to the v0.4 version of next which is a totally different product than one started at v0.9.9.

Issue is that security is reported for packages that still depend on [email protected], which doesn't make sense. It was already discussed here, see #179 for context

Note: I wasn't able to introduce this change via suggest form as it exposes just "Affected versions" field, which logically would have to be >=0.9.9 <13.4.20-canary.13 and that's not accepted

Do not affect `next` versions of previous `next` project
@github-actions github-actions bot changed the base branch from main to medikoo/advisory-improvement-2902 October 31, 2023 20:02
@darakian
Copy link
Contributor

Ah, I see 0.9.9 is the first release after 0.4.x.

@advisory-database advisory-database bot merged commit 4edfd46 into github:medikoo/advisory-improvement-2902 Oct 31, 2023
@advisory-database
Copy link
Contributor

Hi @medikoo! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants