)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"b469df0e76566c3e57c550cadc13f02b907351c8","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"e9419de3_6fe7fc6a","updated":"2026-08-04 21:20:36.000000000","message":"I\u0027ve asked Ironic folks for review on this.","commit_id":"7418da2f50934948e0722be7cdedc8ee2f7ea0cd"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"267efed604b74fb0f317234282a82cbfa4adeebc","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"8c9d5d7d_aed927ea","updated":"2026-08-05 15:41:45.000000000","message":"LGTM, all prior concerns were addressed","commit_id":"bf18583f93bd3b06bbf0f0100059b233e65baa0e"}],"ossa/OSSA-2026-033.yaml":[{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"994a915b3a46596e6cb818f718d903d7041875b4","unresolved":false,"context_lines":[{"line_number":8,"context_line":"  Chen YuXiang of Institute of Computing Technology, Chinese Academy"},{"line_number":9,"context_line":"  of Sciences reported an issue in Ironic\u0027s API. A project reader can"},{"line_number":10,"context_line":"  request a list of portgroups assigned to a shard and all portgroups"},{"line_number":11,"context_line":"  in that shard, not just those in their project, will be returned."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"  This is a similar vulnerability to the one originally advisoried in"},{"line_number":14,"context_line":"  OSSA-2026-026 -- that issue impacted ports; this impacts"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"235d7df4_74e6f895","line":11,"updated":"2026-08-04 21:41:10.000000000","message":"Nit: Your paragraph separator here isn\u0027t kept since you used a folding string type for the description. I don\u0027t know if the break between these is for source maintainability or was also intended to be rendered.","commit_id":"d3c6734bbe3825a2998b6569c34266b4f5d1e673"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"994a915b3a46596e6cb818f718d903d7041875b4","unresolved":false,"context_lines":[{"line_number":16,"context_line":""},{"line_number":17,"context_line":"affected-products:"},{"line_number":18,"context_line":"  - product: ironic"},{"line_number":19,"context_line":"    version: \u0027\u003e\u003d34.0.0 \u003c35.0.2, \u003e\u003d36.0.0 \u003c38.0.1\u0027"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"vulnerabilities:"},{"line_number":22,"context_line":"  - cve-id: \u0027assignment pending\u0027"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"08a017c5_d08cfdb1","line":19,"updated":"2026-08-04 21:41:10.000000000","message":"Can you confirm that the defect was introduced during the 2026.1/gazpacho cycle? That\u0027s implied by the version string here and the lack of backports to any earlier stable branches, but I didn\u0027t see it discussed in the bug report at all.","commit_id":"d3c6734bbe3825a2998b6569c34266b4f5d1e673"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"d6cf6da9afeef256e5d92b5ceba6e9a2d92004b6","unresolved":true,"context_lines":[{"line_number":16,"context_line":""},{"line_number":17,"context_line":"affected-products:"},{"line_number":18,"context_line":"  - product: ironic"},{"line_number":19,"context_line":"    version: \u0027\u003e\u003d34.0.0 \u003c35.0.2, \u003e\u003d36.0.0 \u003c38.0.1\u0027"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"vulnerabilities:"},{"line_number":22,"context_line":"  - cve-id: \u0027assignment pending\u0027"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"829f796d_061463ac","line":19,"in_reply_to":"08a017c5_d08cfdb1","updated":"2026-08-04 21:43:52.000000000","message":"Yep, I can confirm. TBH I was surprised at how recent the feature was, but I can confirm the vulnerable code is not in stable/2025.2.","commit_id":"d3c6734bbe3825a2998b6569c34266b4f5d1e673"},{"author":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"change_message_id":"63b988d06e833a01d392a690f1271a03579ad1b8","unresolved":true,"context_lines":[{"line_number":16,"context_line":""},{"line_number":17,"context_line":"affected-products:"},{"line_number":18,"context_line":"  - product: ironic"},{"line_number":19,"context_line":"    version: \u0027\u003e\u003d34.0.0 \u003c35.0.2, \u003e\u003d36.0.0 \u003c38.0.1\u0027"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"vulnerabilities:"},{"line_number":22,"context_line":"  - cve-id: \u0027assignment pending\u0027"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"f1600d4a_074d6770","line":19,"in_reply_to":"829f796d_061463ac","updated":"2026-08-04 23:15:44.000000000","message":"Yeah we added portgroup filtering recently.","commit_id":"d3c6734bbe3825a2998b6569c34266b4f5d1e673"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"b5818272cbf669454d2ad08063f358ae97908fc3","unresolved":true,"context_lines":[{"line_number":6,"context_line":""},{"line_number":7,"context_line":"description: |"},{"line_number":8,"context_line":"  Chen YuXiang of Institute of Computing Technology, Chinese Academy"},{"line_number":9,"context_line":"  of Sciences reported an issue in Ironic\u0027s API. A project reader can"},{"line_number":10,"context_line":"  request a list of portgroups assigned to a shard and all portgroups"},{"line_number":11,"context_line":"  in that shard, not just those in their project, will be returned."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"  This is a similar vulnerability to the one originally advisoried in"},{"line_number":14,"context_line":"  OSSA-2026-026 -- that issue impacted ports; this impacts"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"720bcf9e_74845051","line":11,"range":{"start_line":9,"start_character":49,"end_line":11,"end_character":67},"updated":"2026-08-05 15:28:05.000000000","message":"I had to read this again because of the sentence structure and then i played it back in your voice :)\n\n\"\nWhen a project reader requests a list of portgroups filtered by shard, all portgroups in that shard are returned, not just those belonging to their project.\n\"\nwould make this clearer.. just a nitpick though","commit_id":"7fcb404c25b86fb523dd5d77fe15a1139161e241"}]}
