Skip to content

[GHSA-jhqm-m4j3-wqq2] Add finder credit (CVE-2026-79655) - #9646

Open
ByteHackr wants to merge 1 commit into
github:ByteHackr/advisory-improvement-9646from
ByteHackr:cve-2026-79655-credit-GHSA-jhqm-m4j3-wqq2
Open

ByteHackr wants to merge 1 commit into
github:ByteHackr/advisory-improvement-9646from
ByteHackr:cve-2026-79655-credit-GHSA-jhqm-m4j3-wqq2

Conversation

@ByteHackr

@ByteHackr ByteHackr commented Sep 20, 2026

Copy link
Copy Markdown

Adds a credits entry crediting Sandipan Roy (@ByteHackr) as FINDER for this advisory.

Public evidence supporting this credit:

Note on affected: intentionally left empty. sos is an OS-level package outside the supported ecosystems (the sos project on PyPI is an unrelated "Script of Scripts" project), and no fixed version exists upstream yet. The credits structure follows the OSV schema and repo convention (e.g. merged PR #7190).

Per CONTRIBUTING.md this PR touches exactly one advisory. Thanks!

@github-actions
github-actions Bot changed the base branch from main to ByteHackr/advisory-improvement-9646 September 20, 2026 19:05
@ByteHackr

Copy link
Copy Markdown
Author

Thanks! Aside from the credit, would the curation team be able to consider this advisory for review (i.e., upgrade it from the NVD mirror entry to a reviewed advisory)? It affects a system/distro package (sos), so I understand ecosystem version-range mapping may be limited, but happy to help with any additional information (affected versions, fixed versions, references) that makes the review possible.

@ByteHackr ByteHackr changed the title Add finder credit for GHSA-jhqm-m4j3-wqq2 [GHSA-jhqm-m4j3-wqq2] Add finder credit for CVE-2026-79655 Sep 20, 2026
@ByteHackr ByteHackr changed the title [GHSA-jhqm-m4j3-wqq2] Add finder credit for CVE-2026-79655 [GHSA-jhqm-m4j3-wqq2] Add finder credit (CVE-2026-79655) Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant