Hi — flagging two repository-level advisories that were published on 2026-08-22 and, eight days later, still return 404 at github.com/advisories/ and are absent from OSV:
GHSA-8c32-52rh-j928 — netcarver/textile (Composer), published by the maintainer, fixed in 4.1.5
GHSA-r4f8-3xc4-c8vw — cloudpathlib (PyPI), published by the maintainer, fixed in 0.25.0
Both are published on their repositories and both have a released fix, so downstream users should be getting a signal. Right now composer audit/Packagist shows nothing for netcarver/textile, and Dependabot shows nothing for cloudpathlib <= 0.24.0.
For comparison, two other advisories I reported were reviewed and ingested quickly — GHSA-r3hx-x5rh-p9vv the same day it published, and GHSA-f2ff-p2ww-7p4p within about two days — so these two look like they may have been missed rather than deliberately held.
Is there anything the maintainers or I need to do on our side, or is this just review backlog? Happy to wait if it's the latter; I mainly wanted to make sure they hadn't fallen out of the queue.
Thanks for maintaining this.
Hi — flagging two repository-level advisories that were published on 2026-08-22 and, eight days later, still return 404 at
github.com/advisories/and are absent from OSV:GHSA-8c32-52rh-j928— netcarver/textile (Composer), published by the maintainer, fixed in 4.1.5GHSA-r4f8-3xc4-c8vw— cloudpathlib (PyPI), published by the maintainer, fixed in 0.25.0Both are published on their repositories and both have a released fix, so downstream users should be getting a signal. Right now
composer audit/Packagist shows nothing fornetcarver/textile, and Dependabot shows nothing forcloudpathlib <= 0.24.0.For comparison, two other advisories I reported were reviewed and ingested quickly —
GHSA-r3hx-x5rh-p9vvthe same day it published, andGHSA-f2ff-p2ww-7p4pwithin about two days — so these two look like they may have been missed rather than deliberately held.Is there anything the maintainers or I need to do on our side, or is this just review backlog? Happy to wait if it's the latter; I mainly wanted to make sure they hadn't fallen out of the queue.
Thanks for maintaining this.