I am requesting a review of GHSA-46qc-4j94-54hf for @bananacool467/ui-tools.
The advisory currently lists:
- Affected versions:
0.1.0-beta through 0.1.7-beta
- Patched versions: None
The historical issue was an unauthenticated WebSocket terminal endpoint. This functionality was intentional, but authentication and security controls were missing from the early implementation.
The package was subsequently updated to address the issue:
- 0.1.9-beta — authentication was added before the WebSocket upgrade / PTY creation.
- 0.2.0-beta — additional security restrictions and hardening were added, including localhost defaults, origin restrictions, session ownership, connection/message/lifetime limits, environment restrictions, and configurable startup behavior.
- 0.2.1-beta — credential verification and additional execution/sandbox controls were added.
I am therefore requesting that the advisory be reviewed to determine whether these releases should be represented as patched/remediated versions rather than showing “Patched versions: None.”
I am not requesting that the historical security issue or affected versions be removed.
I am requesting that the advisory accurately represent the subsequent security fixes and release history.
There is also a separate version-data issue worth reviewing: the advisory itself lists only the eight 0.1.x-beta versions above, while some third-party security aggregators currently display 1.0.0 as affected. 1.0.0 is not listed in this GHSA.
Relevant evidence includes the package's release history and the corresponding security documentation in the repository.
Please review the advisory and determine the appropriate corrected affected/patched version ranges.
I am requesting a review of GHSA-46qc-4j94-54hf for
@bananacool467/ui-tools.The advisory currently lists:
0.1.0-betathrough0.1.7-betaThe historical issue was an unauthenticated WebSocket terminal endpoint. This functionality was intentional, but authentication and security controls were missing from the early implementation.
The package was subsequently updated to address the issue:
I am therefore requesting that the advisory be reviewed to determine whether these releases should be represented as patched/remediated versions rather than showing “Patched versions: None.”
I am not requesting that the historical security issue or affected versions be removed.
I am requesting that the advisory accurately represent the subsequent security fixes and release history.
There is also a separate version-data issue worth reviewing: the advisory itself lists only the eight
0.1.x-betaversions above, while some third-party security aggregators currently display1.0.0as affected.1.0.0is not listed in this GHSA.Relevant evidence includes the package's release history and the corresponding security documentation in the repository.
Please review the advisory and determine the appropriate corrected affected/patched version ranges.