Skip to content

Commit ce7060a

Browse files
Sync Collecting Fix Commits: Wed Aug 12 06:47:20 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 8d42d2a commit ce7060a

8 files changed

Lines changed: 143 additions & 52 deletions

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 99 additions & 33 deletions
Large diffs are not rendered by default.

data/fix-commits/docs-bc355d1d.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
{
22
"vcs_url": "https://github.com/github/docs",
33
"vulnerabilities": {
4+
"GHSA-2V37-7H3G-55P8": {
5+
"a7832252b2d90fb4e5dfa6b8a4641c5ee258bf70": "Bump nanoid to 3.3.17 to fix infinite loop vulnerability (GHSA-2v37-7h3g-55p8) (#62706)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>"
6+
},
47
"GHSA-8988-4F7V-96QF": {
58
"f530144caa72e5dd072f782004d6a11471dd9b5d": "Bump @opentelemetry deps to clear core < 2.8.0 baggage vuln (GHSA-8988-4f7v-96qf) (#62265)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 031a122f-ce90-4f05-8641-f98155428219"
69
},

data/fix-commits/git-e83ef8ed.json

Lines changed: 9 additions & 7 deletions
Large diffs are not rendered by default.

data/fix-commits/langchain-c5a32632.json

Lines changed: 9 additions & 5 deletions
Large diffs are not rendered by default.

data/fix-commits/next.js-dcb792d7.json

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,6 @@
11
{
22
"vcs_url": "https://github.com/vercel/next.js",
33
"vulnerabilities": {
4-
"GHSA-3QHV-2RGH-X77R": {
5-
"665599b0ac81d1a1067aee734c44a6d2137b2c58": "Keep the .npmrc approach for mirror authentication\n\nAn install command writing the token to the user-level pnpm config made vercel deploy fail, so this stays on the repository .npmrc referencing VERCEL_OIDC_TOKEN. The pnpm expansion change (GHSA-3qhv-2rgh-x77r) will need a follow-up once the pinned pnpm moves past 10.33.0.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
6-
"1b426866e7fd54f5b89b94c37dd7f65d5993c2f2": "Configure mirror auth via the install command\n\npnpm no longer expands environment variables in repository .npmrc files (GHSA-3qhv-2rgh-x77r), so referencing VERCEL_OIDC_TOKEN from a generated .npmrc would stop working once the pinned pnpm is updated past 10.33.0. Following the pattern used in vercel/front, deploy tests now write a vercel.json whose install command stores the shell-expanded token in the user-level pnpm config before installing, which keeps working on newer pnpm versions and still keeps credentials out of the uploaded deployment source.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>"
7-
},
84
"GHSA-6G55-P6WH-862Q": {
95
"470ec9acf7f1d3d0719b8e2423e7527f91743c8e": "Bump postcss to 8.5.23 (#96107)\n\nNote that https://github.com/advisories/GHSA-6g55-p6wh-862q does not\naffect Next.js users unless they build from untrusted source code (which\nwould have more severe security implications). We're merging this to\nreduce noise from security scanners.\n\n- 8.5.21 is 50h+ old so it can be installed\n- 8.5.22 is still under 48h - valid at 2026-07-24 08:48:15 UTC \n\nCloses: https://github.com/vercel/next.js/issues/96349\n\nCo-authored-by: Joseph <joseph.chamochumbi@vercel.com>",
106
"5cdcbbb05be0abc21afcb8d5346cc12d854be537": "Bump postcss to 8.5.23 (#96107)\n\nNote that https://github.com/advisories/GHSA-6g55-p6wh-862q does not\naffect Next.js users unless they build from untrusted source code (which\nwould have more severe security implications). We're merging this to\nreduce noise from security scanners.\n\n- 8.5.21 is 50h+ old so it can be installed\n- 8.5.22 is still under 48h - valid at 2026-07-24 08:48:15 UTC \n\nCloses: https://github.com/vercel/next.js/issues/96349"

data/fix-commits/nixpkgs-97436190.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,12 @@
11
{
22
"vcs_url": "https://github.com/nixos/nixpkgs",
33
"vulnerabilities": {
4+
"GHSA-V2X6-M99H-VQXX": {
5+
"d578214c2746c7830918777a16d45074795ac37a": "matrix-continuwuity: 26.7.2 -> 26.7.3\n\nRelease notes: https://forgejo.ellis.link/continuwuation/continuwuity/releases/tag/v26.7.3\nChangelog: https://forgejo.ellis.link/continuwuation/continuwuity/src/commit/v26.7.3/CHANGELOG.md\nDiff: https://forgejo.ellis.link/continuwuation/continuwuity/compare/v26.7.2...v26.7.3\n\nFixes: GHSA-v2x6-m99h-vqxx"
6+
},
7+
"CVE-2026-72522": {
8+
"49076b4ec84292406e66262a7ed7d028dcfe6a6c": "expat: 2.8.2 -> 2.8.3\n\nchangelog: https://github.com/libexpat/libexpat/blob/R_2_8_3/expat/Changes\ndiff: https://github.com/libexpat/libexpat/compare/R_2_8_2...R_2_8_3\n\nFixes: CVE-2026-72522"
9+
},
410
"CVE-2026-61478": {
511
"2e49fce950fece113519c5d75da869601d01550f": "[release-26.05] libvirt: fix CVE-2026-61478 and CVE-2026-61477 (#551428)",
612
"fb45cd4fccdc0404c032288c544a8a1e72908686": "libvirt: fix CVE-2026-61478 and CVE-2026-61477\n\nThese patches are from the upcoming 12.6 release of libvirt and apply\ncleanly.\n\nFixes: CVE-2026-61478\nFixes: CVE-2026-61477\nNot-cherry-picked-because: Unstable is already on newer libvirt versions"

data/fix-commits/nltk-79cc9cf1.json

Lines changed: 11 additions & 3 deletions
Large diffs are not rendered by default.

data/fix-commits/spark-9ac9c533.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,12 @@
11
{
22
"vcs_url": "https://github.com/apache/spark",
33
"vulnerabilities": {
4+
"CVE-2026-71847": {
5+
"5eb01f1b1412ed7ea319898da41d13710889d922": "[SPARK-58727][DOC] Update `json` gem version to 2.21.2\n\n### What changes were proposed in this pull request?\n\nThis PR upgrades the `json` gem from 2.21.1 to 2.21.2 in `docs/Gemfile.lock`. It is a transitive dependency (pulled in by `jekyll`, which requires `json (~> 2.6)`), and 2.21.2 satisfies that constraint, so only the locked spec version changes.\n\n`json` has no runtime dependencies, so no other lock entries change and `docs/Gemfile` does not need to be touched.\n\n### Why are the changes needed?\n\n2.21.2 includes the fix for a security advisory that affects `>= 2.20.0, <= 2.21.1`:\n\n- [GHSA-9hj4-r449-hfvc](https://github.com/advisories/GHSA-9hj4-r449-hfvc) / CVE-2026-71847 (low): heap use-after-free in the native C extension's `JSON::ResumableParser`. When the current input buffer is consumed, `cResumableParser_parse` calls `json_str_clear(parser->buffer)` and drops the reference but leaves `state.start`, `state.cursor`, and `state.end` pointing into the released storage. If `partial_value` then reconstructs an incomplete object containing duplicate keys, the duplicate-key warning path reaches `cursor_position`, which dereferences those stale pointers and can terminate the process. Fixed in 2.21.2.\n\nThis addresses https://github.com/apache/spark/security/dependabot/227.\n\nFollowing the same pattern as SPARK-58371 (`json` 2.21.1) and SPARK-57633 (`concurrent-ruby` 1.3.7), this picks up the latest release, which here is also the minimum patched version.\n\n### Does this PR introduce _any_ user-facing change?\n\nNo. This only affects the documentation build toolchain.\n\n### How was this patch tested?\n\nManually verified against `docs/Gemfile` and `docs/Gemfile.lock`:\n\n1. Lock resolution matches. `bundle lock --update=json` resolves `json` to exactly 2.21.2 and touches no other locked spec, confirming 2.21.2 satisfies jekyll's `json (~> 2.6)`. The committed lock is a one-line hand edit so the local Bundler version does not rewrite the `RUBY VERSION` / `BUNDLED WITH` stanzas.\n\n2. Frozen install succeeds. `BUNDLE_FROZEN=true bundle install` installs all 36 gems without modifying the lock file, and `bundle list` reports `json (2.21.2)`.\n\n3. The docs site builds:\n\n```\n$ cd docs && SKIP_API=1 bundle exec jekyll build\nConfiguration file: .../docs/_config.yml\n\n************************\n* Building error docs. *\n************************\nGenerated: docs/_generated/error-conditions.html\n Source: .../docs\n Destination: .../docs/_site\n Incremental build: disabled. Enable with --incremental\n Generating...\nWarning: Tolerating missing API files because the following skip flags are set: SKIP_API\n done in 3.207 seconds.\n Auto-regeneration: disabled. Use --watch to enable.\n```\n\n4. Ran the advisory's `JSON::ResumableParser` sequence (two chunks so the first buffer is consumed and cleared, incomplete trailing object, duplicate key, heap churn plus `GC.start` before `partial_value`) against both 2.21.1 and 2.21.2. Both complete without crashing on this platform, so this is not a local reproduction of the use-after-free -- the advisory's own evidence for the release-build crash is an AddressSanitizer build. The check confirms the version bump does not regress the `ResumableParser` duplicate-key path.\n\n5. Pass GitHub Actions.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nGenerated-by: Claude Code (Opus 5)\n\nCloses #57951 from LuciferYang/docs-json-gem-2.21.2.\n\nAuthored-by: YangJie <yangjie01@baidu.com>\nSigned-off-by: yangjie01 <yangjie01@baidu.com>"
6+
},
7+
"GHSA-9HJ4-R449-HFVC": {
8+
"5eb01f1b1412ed7ea319898da41d13710889d922": "[SPARK-58727][DOC] Update `json` gem version to 2.21.2\n\n### What changes were proposed in this pull request?\n\nThis PR upgrades the `json` gem from 2.21.1 to 2.21.2 in `docs/Gemfile.lock`. It is a transitive dependency (pulled in by `jekyll`, which requires `json (~> 2.6)`), and 2.21.2 satisfies that constraint, so only the locked spec version changes.\n\n`json` has no runtime dependencies, so no other lock entries change and `docs/Gemfile` does not need to be touched.\n\n### Why are the changes needed?\n\n2.21.2 includes the fix for a security advisory that affects `>= 2.20.0, <= 2.21.1`:\n\n- [GHSA-9hj4-r449-hfvc](https://github.com/advisories/GHSA-9hj4-r449-hfvc) / CVE-2026-71847 (low): heap use-after-free in the native C extension's `JSON::ResumableParser`. When the current input buffer is consumed, `cResumableParser_parse` calls `json_str_clear(parser->buffer)` and drops the reference but leaves `state.start`, `state.cursor`, and `state.end` pointing into the released storage. If `partial_value` then reconstructs an incomplete object containing duplicate keys, the duplicate-key warning path reaches `cursor_position`, which dereferences those stale pointers and can terminate the process. Fixed in 2.21.2.\n\nThis addresses https://github.com/apache/spark/security/dependabot/227.\n\nFollowing the same pattern as SPARK-58371 (`json` 2.21.1) and SPARK-57633 (`concurrent-ruby` 1.3.7), this picks up the latest release, which here is also the minimum patched version.\n\n### Does this PR introduce _any_ user-facing change?\n\nNo. This only affects the documentation build toolchain.\n\n### How was this patch tested?\n\nManually verified against `docs/Gemfile` and `docs/Gemfile.lock`:\n\n1. Lock resolution matches. `bundle lock --update=json` resolves `json` to exactly 2.21.2 and touches no other locked spec, confirming 2.21.2 satisfies jekyll's `json (~> 2.6)`. The committed lock is a one-line hand edit so the local Bundler version does not rewrite the `RUBY VERSION` / `BUNDLED WITH` stanzas.\n\n2. Frozen install succeeds. `BUNDLE_FROZEN=true bundle install` installs all 36 gems without modifying the lock file, and `bundle list` reports `json (2.21.2)`.\n\n3. The docs site builds:\n\n```\n$ cd docs && SKIP_API=1 bundle exec jekyll build\nConfiguration file: .../docs/_config.yml\n\n************************\n* Building error docs. *\n************************\nGenerated: docs/_generated/error-conditions.html\n Source: .../docs\n Destination: .../docs/_site\n Incremental build: disabled. Enable with --incremental\n Generating...\nWarning: Tolerating missing API files because the following skip flags are set: SKIP_API\n done in 3.207 seconds.\n Auto-regeneration: disabled. Use --watch to enable.\n```\n\n4. Ran the advisory's `JSON::ResumableParser` sequence (two chunks so the first buffer is consumed and cleared, incomplete trailing object, duplicate key, heap churn plus `GC.start` before `partial_value`) against both 2.21.1 and 2.21.2. Both complete without crashing on this platform, so this is not a local reproduction of the use-after-free -- the advisory's own evidence for the release-build crash is an AddressSanitizer build. The check confirms the version bump does not regress the `ResumableParser` duplicate-key path.\n\n5. Pass GitHub Actions.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nGenerated-by: Claude Code (Opus 5)\n\nCloses #57951 from LuciferYang/docs-json-gem-2.21.2.\n\nAuthored-by: YangJie <yangjie01@baidu.com>\nSigned-off-by: yangjie01 <yangjie01@baidu.com>"
9+
},
410
"GHSA-6CX8-RJF8-PR8G": {
511
"2e6d44f77abaa35786999bddb1002276303752ca": "[SPARK-58665][BUILD] Upgrade `lz4-java` to 1.11.2\n\n### What changes were proposed in this pull request?\n\nThis PR aims to upgrade `at.yawk.lz4:lz4-java` to 1.11.2.\n\n### Why are the changes needed?\n\nThis is a security release to bring the latest security fixes from the following release.\n\n- https://github.com/yawkat/lz4-java/releases/tag/v1.11.2 (2026-08-06)\n - [LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError](https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g)\n - [LZ4BlockInputStream allocates an unvalidated compressed length from the stream header](https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464)\n\n**Full Changelog**: https://github.com/yawkat/lz4-java/compare/v1.11.1...v1.11.2\n\n### Does this PR introduce _any_ user-facing change?\n\nNo.\n\n### How was this patch tested?\n\nPass the CIs.\n\n### Was this patch authored or co-authored using generative AI tooling?\n\nGenerated-by: Claude Fable 5\n\nCloses #57874 from dongjoon-hyun/dongjoon/upgrade-lz4-java-66a987.\n\nAuthored-by: Dongjoon Hyun <dongjoon@apache.org>\nSigned-off-by: Dongjoon Hyun <dongjoon@apache.org>"
612
},

0 commit comments

Comments
 (0)