Repository navigation
Conversation
|
Hi there @mpilquist! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
|
sorry i didn't realize github was going to tag people in I'm trying to provide feedback on GitHub's incorrect detection of an issue |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The advisory details improperly include a project-specific dependency-alert complaint.
Review effort: Balanced
Findings: 1
What changed in this PR
Updates the FS2 security advisory’s affected package entries and description.
Changes:
- Reorders FS2 artifact/version range associations.
- Adds a consumer-specific note to the advisory details.
- Updates the modification timestamp.
| File | Description |
|---|---|
GHSA-rrw2-px9j-qffj.json |
Updates advisory metadata, details, and affected package ordering. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| ], | ||
| "summary": "FS2 half-shutdown of socket during TLS handshake may result in spin loop on opposite side", | ||
| "details": "### Impact\nWhen establishing a TLS session using `fs2-io` on the JVM using the `fs2.io.net.tls` package, if one side of the connection shuts down write while the peer side is awaiting more data to progress the TLS handshake, the peer side will spin loop on the socket read, fully utilizing a CPU. This CPU is consumed until the overall connection is closed.\n\nThis could be used as a denial of service attack on an fs2-io powered server -- for example, by opening many connections and putting them in a half-shutdown state.\n\nNote: this issue impacts ember backed http4s servers with HTTPS as a result of ember using fs2's TLS support.\n\n### Patches\nFixed in fs2 3.12.2 and 3.13.0-M7.\n\n### Workarounds\nNo workarounds.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n[Open an issue.](https://github.com/typelevel/fs2/issues/new/choose)\nContact the [Typelevel Security Team](https://github.com/typelevel/.github/blob/main/SECURITY.md).", | ||
| "details": "I'm not sure how you're getting this but the build for my project clearly explicitly pins a newer version than this advisory affects.\n\n### Impact\nWhen establishing a TLS session using `fs2-io` on the JVM using the `fs2.io.net.tls` package, if one side of the connection shuts down write while the peer side is awaiting more data to progress the TLS handshake, the peer side will spin loop on the socket read, fully utilizing a CPU. This CPU is consumed until the overall connection is closed.\n\nThis could be used as a denial of service attack on an fs2-io powered server -- for example, by opening many connections and putting them in a half-shutdown state.\n\nNote: this issue impacts ember backed http4s servers with HTTPS as a result of ember using fs2's TLS support.\n\n### Patches\nFixed in fs2 3.12.2 and 3.13.0-M7.\n\n### Workarounds\nNo workarounds.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n[Open an issue.](https://github.com/typelevel/fs2/issues/new/choose)\nContact the [Typelevel Security Team](https://github.com/typelevel/.github/blob/main/SECURITY.md).", |

Updates
Comments
My build clearly pins to a version of the library that is not affected by this advisory.