Skip to content

[GHSA-vccv-cmxp-4j9h] sanitize-html: align described affected versions with the recorded range (through 2.17.4, fixed in 2.17.5) - #8961

Open
pacocartones wants to merge 1 commit into
github:pacocartones/advisory-improvement-8961from
pacocartones:codex/clarify-sanitize-html-range
Open

[GHSA-vccv-cmxp-4j9h] sanitize-html: align described affected versions with the recorded range (through 2.17.4, fixed in 2.17.5)#8961
pacocartones wants to merge 1 commit into
github:pacocartones/advisory-improvement-8961from
pacocartones:codex/clarify-sanitize-html-range

Conversation

@pacocartones

@pacocartones pacocartones commented Aug 3, 2026

Copy link
Copy Markdown

Updates

  • Description

Comments
The description states that affected versions run "through at least v2.17.2", while the structured npm range in the same advisory already records >= 1.18.0, < 2.17.5, with 2.17.4 as the last affected version. This aligns the prose with the range that is already there and names 2.17.5 as the first patched release.

Sources, both already referenced by the advisory:

No package, ecosystem, severity, CWE, CVSS or machine-readable range metadata is changed — only the human-readable text, so that it stops contradicting the structured data next to it.

@github-actions
github-actions Bot changed the base branch from main to pacocartones/advisory-improvement-8961 August 3, 2026 11:52
@pacocartones
pacocartones marked this pull request as ready for review August 3, 2026 12:14
@pacocartones pacocartones changed the title Clarify sanitize-html affected version range [GHSA-vccv-cmxp-4j9h] sanitize-html: align described affected versions with the recorded range (through 2.17.4, fixed in 2.17.5) Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant