Skip to content

Comments

Fix for GHSA-378v-28hj-76wf has been backported to bn.js 4.12.3#7025

Open
jochenschmich-aeberle wants to merge 1 commit intogithub:jochenschmich-aeberle/advisory-improvement-7025from
jochenschmich-aeberle:jochenschmich-aeberle-GHSA-378v-28hj-76wf
Open

Fix for GHSA-378v-28hj-76wf has been backported to bn.js 4.12.3#7025
jochenschmich-aeberle wants to merge 1 commit intogithub:jochenschmich-aeberle/advisory-improvement-7025from
jochenschmich-aeberle:jochenschmich-aeberle-GHSA-378v-28hj-76wf

Conversation

@jochenschmich-aeberle
Copy link

The fix for GHSA-378v-28hj-76wf is not only available for 5.2.3. It's also been fixed for 4.12.3.
See: indutny/bn.js@67ecb35

Some libraries depend on version 4.x, so this fix might be important for several dependents.

Copilot AI review requested due to automatic review settings February 23, 2026 14:50
@github-actions github-actions bot changed the base branch from main to jochenschmich-aeberle/advisory-improvement-7025 February 23, 2026 14:51
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the OSV/GitHub-reviewed advisory for bn.js (GHSA-378v-28hj-76wf) to reflect that the upstream fix was also backported to the 4.x line, not just 5.x.

Changes:

  • Update advisory details to mention the 4.12.3 backport.
  • Split the affected version ranges to reflect fixes in both 4.12.3 (4.x) and 5.2.3 (5.x).
  • Add an additional upstream reference commit for the 4.x backport.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@jochenschmich-aeberle jochenschmich-aeberle force-pushed the jochenschmich-aeberle-GHSA-378v-28hj-76wf branch from ccc95a8 to c0ecaa7 Compare February 23, 2026 14:58
@jochenschmich-aeberle jochenschmich-aeberle force-pushed the jochenschmich-aeberle-GHSA-378v-28hj-76wf branch from c0ecaa7 to dbdacb4 Compare February 23, 2026 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant