Skip to content

Conversation

@robherley
Copy link

@robherley robherley commented Feb 2, 2026

Updates

  • Affected products

Comments
The sandbox package has changed owners and is now an SDK for Vercel Sandbox. The exploits are not relevant to the new package versions.

Copilot AI review requested due to automatic review settings February 2, 2026 23:04
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates a GitHub Security Advisory (GHSA) for the sandbox npm package to reflect that the vulnerability has been resolved in version 1.0.0 and later. The package has changed ownership and is now a Vercel Sandbox SDK, making the original exploits no longer applicable.

Changes:

  • Updated the modification timestamp to reflect the advisory change
  • Added a "fixed" version constraint indicating the vulnerability is resolved in versions >= 1.0.0

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions github-actions bot changed the base branch from main to robherley/advisory-improvement-6759 February 2, 2026 23:05
@advisory-database advisory-database bot merged commit 17d21b9 into robherley/advisory-improvement-6759 Feb 2, 2026
5 checks passed
@advisory-database
Copy link
Contributor

Hi @robherley! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the robherley-GHSA-gc25-3vc5-2jf9 branch February 2, 2026 23:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants