diff --git a/lib/github_advisory_sync.rb b/lib/github_advisory_sync.rb index 65dbf5e156..3bff1ad13a 100644 --- a/lib/github_advisory_sync.rb +++ b/lib/github_advisory_sync.rb @@ -196,7 +196,18 @@ def updating? end def filename - File.join("gems", name, "#{@advisory.primary_id}.yml") + # These packages appear to have been named differently in the past + # This 'corrects' them so updates don't affect existing vulnerabilities + package_name = case name + when "arabic-prawn" + "Arabic-Prawn" + when "redcloth" + "RedCloth" + else + name + end + + File.join("gems", package_name, "#{@advisory.primary_id}.yml") end def framework @@ -414,7 +425,7 @@ def create(package) # populate the related information new_data["related"] = { - "url" => advisory["references"] + "url" => advisory["references"].map { |reference| reference['url'] }.reject(&:empty?) } FileUtils.mkdir_p(File.dirname(filename_to_write))