Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump Nokogiri version #149

Closed
wants to merge 1 commit into from
Closed

Bump Nokogiri version #149

wants to merge 1 commit into from

Conversation

adriendumont
Copy link

Nokogiri has a serious security flaw that was fixed on 1.10.4 sparklemotion/nokogiri#1915

I've bumped the nokogiri version is all packages

@msftclas
Copy link

msftclas commented Dec 18, 2019

CLA assistant check
All CLA requirements met.

@coveralls
Copy link

Coverage Status

Coverage remained the same at ?% when pulling 7c4d336 on adriendumont:bump-nokogiri-version into df9c2cb on Azure:master.

@katmsft
Copy link
Member

katmsft commented Mar 10, 2020

This version bump is released in azure-storage-common v2.0.1, and will be closed shortly. Thanks for letting us know the issue.

@katmsft
Copy link
Member

katmsft commented Mar 10, 2020

The reason we did not take this PR is that we deprecate the support of v2.3.0 in the latest release and used ~>1.10.4 instead of ~>1.10, due to the fact that Nokogiri may choose to deprecate Ruby runtime versions in minor releases, but not in hotfix releases.
We really appreciate you raising this PR and letting us know the issue. We will close this PR as it is no longer valid, and we look forward to future collaboration on this SDK!

@vinjiang vinjiang closed this Mar 10, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants