Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-6q8c-85p2-954c] In Progress Telerik UI for WPF versions prior to 2024 Q3 ... #5087

Conversation

LanceMcCarthy
Copy link

Updates

  • Affected products
  • Description
  • Summary

Comments
The advisory was missing critical information such as version and package name. I am a representative of Progress Software, which can be confirmed by finding me in https://github.com/orgs/telerik/people or viewing my profile's Organizations list.

Note: The package is not available via nuget.org, it is provided by a private NuGet feed (nuget.telerik.com). Therefore, the package name match feature of this item will not find a match.

@github-actions github-actions bot changed the base branch from main to LanceMcCarthy/advisory-improvement-5087 December 16, 2024 13:53
@JonathanLEvans
Copy link

Hi @LanceMcCarthy, thank you for your contribution. We cannot use wildcards in package names. Could you provide the full name for each affected package in NuGet?

@LanceMcCarthy
Copy link
Author

Hi @JonathanLEvans there are maybe 20 packages for this release (different versions of .NET, trials, etc), I will prepare the full list and update this thread as soon as it is ready.

@LanceMcCarthy
Copy link
Author

LanceMcCarthy commented Dec 17, 2024

Hello @JonathanLEvans I can't seem to find an easy way to edit the PR. so I have closed this PR, forked the repo and opened a new PR with the requested update.

=> #5094

[followup] I plan on reviewing and updating many of these https://github.com/advisories?page=1&query=type%3Aunreviewed+telerik. Is it better I open a single PR with all of the changes? Or a separate PR for each advisory?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants