Information on Helping To Improve External Data

June 15, 2026 ยท View on GitHub

Remember that these requests are outside the scope of the ruby-advisory-db repo.

Here are the different sources of information this repo usually uses and how to request a change if needed.

GENERAL

  • Missing CVE number (also just "reserved" CVE with no details)
    • Google CVE number, check cve.org and nvd.nist.gov web sites
  • Missing GHSA number
    • Google GHSA number, check GHSA web site.
  • Missing patch release
    • See repo README on policy.
  • Have only project-specific data (announcement, blog, CHANGELOG, Release notes) about advisory
    • Google for more information. Try to contact developer privately.
  • To exclude a duplicate or disputed advisories, create a PR to add them to file.

GEMS

RUBIES (ruby, jruby, mruby, rubinius/rbx, etc)

Feel free to suggest more scenarios to add or better words/etc to improve existing scenarios.