Avoid using > operator in affected version ranges for advisories

Created on 5 August 2025, 19 days ago

While ingesting advisories into https://github.com/ackama/drupal-advisory-database we've identified a handful with affected versions that use the > operator as part of a range - while not technically invalid, it does not capture the exact version that the vulnerability was introduced (and so far I believe all the usages we've found have meant a vulnerable version is excluded).

Ideally the >= operator should be preferred instead:

πŸ› Bug report
Status

Active

Version

1.0

Component

Code

Created by

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024