Skip to content

Conversation

@tockn
Copy link

@tockn tockn commented Dec 4, 2025

Summary

This PR adds CVE-2025-55182 as an alias to this advisory.

Details

According to NVD, CVE-2025-66478 has been REJECTED as a duplicate of CVE-2025-55182.
This change adds the active CVE ID to the aliases to correctly map this vulnerability.

References

Copilot AI review requested due to automatic review settings December 4, 2025 08:59
@github-actions github-actions bot changed the base branch from main to tockn/advisory-improvement-6496 December 4, 2025 09:00
Copilot finished reviewing on behalf of tockn December 4, 2025 09:03
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the security advisory GHSA-9qr9-h5gf-34mp to replace a rejected CVE ID with the active one. CVE-2025-66478 was rejected by NVD as a duplicate of CVE-2025-55182, so both IDs are now listed as aliases to ensure proper vulnerability tracking.

Key changes:


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@mswilson
Copy link

mswilson commented Dec 4, 2025

Per the OSV schema, https://ossf.github.io/osv-schema/#aliases-field

Aliases should not be used to refer to vulnerabilities in packages upstream or downstream in a software supply chain from the given OSV record’s affected package(s). For example, if a CVE describes a vulnerability in a language library, and a Linux distribution package contains that library and therefore publishes an advisory, the distribution’s OSV record must not list the CVE ID as an alias. Similarly, distributions often bundle multiple upstream vulnerabilities into a single record. To refer to these upstream vulnerabilities, upstream should be used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants