Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump Addressable from 2.3.6 to 2.8.0 #948

Merged
merged 1 commit into from Aug 2, 2021

Conversation

EduardoGHdez
Copy link
Contributor

@EduardoGHdez EduardoGHdez commented Jul 16, 2021

This version fixes a ReDoS vulnerability in Addressable::Template#match

For more information about the issue:

From addressable CHANGELOG, it seems to not have breaking changes, and just ran the test-suite passed in my local without failures ✅

This version fixes a ReDoS vulnerability in Addressable::Template#match

For more information about the issue:
- https://app.snyk.io/vuln/SNYK-RUBY-ADDRESSABLE-1316242
@dilumn
Copy link

dilumn commented Jul 31, 2021

Hi any plans to merge this change & do a new release?

@bblimke bblimke merged commit 3a5c8a3 into bblimke:master Aug 2, 2021
@bblimke
Copy link
Owner

bblimke commented Aug 2, 2021

Thank you @EduardoGHdez

@yidingww
Copy link

yidingww commented Aug 5, 2021

@bblimke Hellooo, can we have a new release of this? 👀 Thanks!

@bblimke
Copy link
Owner

bblimke commented Aug 5, 2021

@yidingww done

@yidingww
Copy link

yidingww commented Aug 5, 2021

@bblimke Thank you!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants