Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| https://github.com/reviewdog/action-ast-grep | affected | < 5139a664d8891a080f67b78c6e6e85ccb2e002f6 | vendor fix → 5139a664d8891a080f67b78c6e6e85ccb2e002f6 | osv | |
| https://github.com/reviewdog/action-ast-grep | affected | < e8f0e0a5f62a05a6d9e4bd84c4b6e582b8091e23 | vendor fix → e8f0e0a5f62a05a6d9e4bd84c4b6e582b8091e23 | osv | |
| https://github.com/reviewdog/action-ast-grep | affected | >= d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f, < 3f401fe1d58fe77e10d665ab713057375e39b887 | vendor fix → 3f401fe1d58fe77e10d665ab713057375e39b887 | osv | |
| https://github.com/reviewdog/action-ast-grep | affected | < f0d342d24037bb11d26b9bd8496e0808ba32e9ec | vendor fix → f0d342d24037bb11d26b9bd8496e0808ba32e9ec | osv | |
| https://github.com/reviewdog/action-ast-grep | affected | < 1081fc2953db00c6756f750e09563b49a8a09408 | vendor fix → 1081fc2953db00c6756f750e09563b49a8a09408 | osv | |
| https://github.com/reviewdog/action-ast-grep | affected | < f106cde0d7fe94c0eeb49352ee7ba9b19c7021d1 | vendor fix → f106cde0d7fe94c0eeb49352ee7ba9b19c7021d1 | osv | |
| https://github.com/reviewdog/action-ast-grep | affected | < 627388e238f182b925d9acd151432f9b68f1d666 | vendor fix → 627388e238f182b925d9acd151432f9b68f1d666 | osv | |
| reviewdog/action-setup | affected | 1 | none available | osv GHSA-qmg3-hpqr-gqvc | |
| https://github.com/reviewdog/action-ast-grep | fixed | 5139a664d8891a080f67b78c6e6e85ccb2e002f6 | vendor fix → 5139a664d8891a080f67b78c6e6e85ccb2e002f6 | osv | |
| https://github.com/reviewdog/action-ast-grep | fixed | e8f0e0a5f62a05a6d9e4bd84c4b6e582b8091e23 | vendor fix → e8f0e0a5f62a05a6d9e4bd84c4b6e582b8091e23 | osv | |
| https://github.com/reviewdog/action-ast-grep | fixed | 3f401fe1d58fe77e10d665ab713057375e39b887 | vendor fix → 3f401fe1d58fe77e10d665ab713057375e39b887 | osv | |
| https://github.com/reviewdog/action-ast-grep | fixed | f0d342d24037bb11d26b9bd8496e0808ba32e9ec | vendor fix → f0d342d24037bb11d26b9bd8496e0808ba32e9ec | osv | |
| https://github.com/reviewdog/action-ast-grep | fixed | 1081fc2953db00c6756f750e09563b49a8a09408 | vendor fix → 1081fc2953db00c6756f750e09563b49a8a09408 | osv | |
| https://github.com/reviewdog/action-ast-grep | fixed | f106cde0d7fe94c0eeb49352ee7ba9b19c7021d1 | vendor fix → f106cde0d7fe94c0eeb49352ee7ba9b19c7021d1 | osv | |
| https://github.com/reviewdog/action-ast-grep | fixed | 627388e238f182b925d9acd151432f9b68f1d666 | vendor fix → 627388e238f182b925d9acd151432f9b68f1d666 | osv | |
| reviewdog/reviewdog reviewdog · reviewdog | affected | = 1 | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.