[GHSA-c8q4-9h32-2ww8] Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types#8088
Conversation
|
Hi there @jasonmcintosh! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
Pull request overview
This PR corrects a typo in the GitHub Security Advisory JSON for GHSA-c8q4-9h32-2ww8, ensuring the advisory summary accurately describes the unsafe YAML deserialization issue.
Changes:
- Fixes the summary text typo (“uon-safe” → “unsafe”).
- Updates the
modifiedtimestamp to reflect the edit.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Updates
Comments
Typo in the original GHSA title