GHSA-rggj-c47j-46v9 is published and its patched_versions is set to 0.8.0, so the disclosure itself is complete. No CVE has been requested: the advisory still reports cve: none.
GitHub can assign one as a CNA from the advisory page ("Request CVE"), which makes the issue citable outside GitHub and picks it up in downstream vulnerability databases and SCA tooling.
Worth deciding rather than leaving implicit. Either request it, or note on the advisory that a CVE is deliberately not being sought.
Filed while archiving the bound-flow-session-state change, whose task 7.3 covered coordinating this. That change lives under openspec/, which is gitignored, so the task would not have survived the archive.
Related: #480.
GHSA-rggj-c47j-46v9is published and itspatched_versionsis set to0.8.0, so the disclosure itself is complete. No CVE has been requested: the advisory still reportscve: none.GitHub can assign one as a CNA from the advisory page ("Request CVE"), which makes the issue citable outside GitHub and picks it up in downstream vulnerability databases and SCA tooling.
Worth deciding rather than leaving implicit. Either request it, or note on the advisory that a CVE is deliberately not being sought.
Filed while archiving the
bound-flow-session-statechange, whose task 7.3 covered coordinating this. That change lives underopenspec/, which is gitignored, so the task would not have survived the archive.Related: #480.