Skip to content

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Dec 20, 2025

Fixed problem URLs in gems advisories. See details below.

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noticed some issues.

  • I prefer that the canonical URL be to either NVD, or GHSA, or the project's own announcement. Web Archive URLs of old blog posts may go into the related URLs section.
  • Some of the blogs moved to different domains and I was able to find the old blog posts.
  • One URL is still alive and was mistakenly removed.

cve: 2015-7519
ghsa: fxwv-953p-7qpf
url: https://blog.phusion.nl/2015/12/07/cve-2015-7519/
url: https://web.archive.org/web/20220327073056/https://www.puppet.com/security/cve/passenger-dec-2015-security-fixes
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's better to link to either NVD or the GHSA advisory as the canonical URL, instead of Web Archive. It's OK to list a Web Archive link in the related URLs.

cve: 2009-2422
ghsa: rxq3-gm4p-5fj4
url: http://weblog.rubyonrails.org/2009/6/3/security-problem-with-authenticate_with_http_digest
url: https://github.com/advisories/GHSA-rxq3-gm4p-5fj4
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2009-2422
- http://weblog.rubyonrails.org/2009/6/3/security-problem-with-authenticate_with_http_digest
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

- ">= 1.3.1"
related:
url:
- http://blog.steveklabnik.com/posts/2013-08-03-redis-namespace-1-3-1--security-release
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

osvdb: 81505
ghsa: 7h48-m3rw-vr27
url: https://spreecommerce.com/blog/security-vulnerability-mass-assignment
url: https://web.archive.org/web/20101128024717/http://spreecommerce.com/blog/2008/09/16/security-vulnerability-mass-assignment-of-order-params
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The canonical URL should link to either NVD or GHSA. Web Archive links can go in the related URLs section.

cve: 2013-2506
osvdb: 90865
url: https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed
url: https://web.archive.org/web/20160331131233/https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The canonical URL should link to either NVD or GHSA. Web Archive links can go in the related URLs section.

cve: 2013-2506
osvdb: 90865
url: https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed
url: https://web.archive.org/web/20160331131233/https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The canonical URL should link to either NVD or GHSA. Web Archive links can go in the related URLs section.

osvdb: 90865
ghsa: jp57-9j37-5476
url: https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed
url: https://web.archive.org/web/20160331131233/https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The canonical URL should link to either NVD or GHSA. Web Archive links can go in the related URLs section.

related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2015-8857
- https://github.com/mishoo/UglifyJS/issues/751
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This URL is still alive. Worth keeping it in the related URLs section.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants