Skip to content

Conversation

@dnegreira
Copy link

Updates

  • Affected products
  • Description
  • References
  • Source code location
  • Summary

Comments
The CVE number is referring to RoadRunner which is not what this CVE references which is the golang package itself.

@github-actions github-actions bot changed the base branch from main to dnegreira/advisory-improvement-6490 December 2, 2025 13:39
@yhidad31
Copy link

yhidad31 commented Dec 5, 2025

Hello @dnegreira , this advisory was updated by a project maintainer to reflect the vulnerability in spiral/roadrunner. The http Go package is not in scope of the GitHub Advisory Datatabase's coverage as it is a standard library, and we only publish Go modules (see https://pkg.go.dev/net/http. Please see this issue and this supported ecosystems documentation for details.

@yhidad31 yhidad31 closed this Dec 5, 2025
@github-actions github-actions bot deleted the dnegreira-GHSA-g9pc-8g42-g6vq branch December 5, 2025 22:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants