Skip to content

[GHSA-w54x-xfxg-4gxq] NeuVector process with sensitive arguments lead to leakage#7800

Open
holyspectral wants to merge 1 commit into
holyspectral/advisory-improvement-7800from
holyspectral-GHSA-w54x-xfxg-4gxq
Open

[GHSA-w54x-xfxg-4gxq] NeuVector process with sensitive arguments lead to leakage#7800
holyspectral wants to merge 1 commit into
holyspectral/advisory-improvement-7800from
holyspectral-GHSA-w54x-xfxg-4gxq

Conversation

@holyspectral
Copy link
Copy Markdown

Updates

  • Affected products

Comments
The 5.0.0 and 5.4.6 version point to invalid golang module versions. The issue has been fixed in the upstream advisory by chaning the type to other GHSA-w54x-xfxg-4gxq .

Copilot AI review requested due to automatic review settings May 22, 2026 14:22
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates the GHSA advisory record by removing one previously listed affected package entry, likely to correct the set of impacted modules/versions.

Changes:

  • Removed the github.com/neuvector/neuvector affected package range (introduced: 5.0.0fixed: 5.4.6) from the advisory JSON.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions github-actions Bot changed the base branch from main to holyspectral/advisory-improvement-7800 May 22, 2026 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants