Hello,
I noticed that the advisory GHSA-9mvj-f7w8-pvh2 is still listed in the GitHub Advisory Database, but the corresponding CVE entry in NVD has been marked as rejected.
Reference: NVD entry
I’d like to better understand:
-
Will the GitHub advisory be updated to reflect the rejection, or is there a reason for keeping it active here?
-
How does the synchronization process between NVD and GitHub Advisory Database usually work?
-
In cases like this, what is the expected timeline for updates?
Thank you for your clarification and for maintaining the database.