Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update required version of addressable to 2.8 #584

Merged
merged 1 commit into from Aug 6, 2021
Merged

Update required version of addressable to 2.8 #584

merged 1 commit into from Aug 6, 2021

Conversation

yidingww
Copy link
Contributor

@yidingww yidingww commented Jul 30, 2021

@flavorjones

There is high severity security issue about addressable 2.7.0 and below: GHSA-jxhc-q857-3j6g

So update required addressable to 2.8

@flavorjones
Copy link
Member

@yidingww Thank you for this pull request! I'm going to look into why Dependabot didn't catch this before now.

@flavorjones
Copy link
Member

I've enabled dependabot updates in 3f046bd and just now turned on security alerts as well. I'm going to give that a bit of time to see if it catches the vulnerable addressable versions.

@yidingww
Copy link
Contributor Author

yidingww commented Aug 5, 2021

@flavorjones Helloo, any plans to merge this soon and do a new release? :)

@flavorjones
Copy link
Member

Dependabot hasn't raised an alert about Addressable, and I don't understand why. Sigh.

Merging now.

@flavorjones flavorjones merged commit 9640de7 into sparklemotion:main Aug 6, 2021
@flavorjones
Copy link
Member

@yidingww I'm not sure this change requires a release. The vulnerability in Addressable is in Addressable::Template#match which Mechanize doesn't use, so there's no attack vector in Mechanize.

@yidingww
Copy link
Contributor Author

yidingww commented Aug 6, 2021

@flavorjones Ah I see.

But we have a security scanning at our organisation that force us to use packaged rely on addressable 2.8 and above. So i would appreciate a lot if you could make a new release if it's convenient for you 😉

@flavorjones
Copy link
Member

@yidingww yidingww deleted the update-required-version-of-addressable branch August 7, 2021 02:56
@yidingww
Copy link
Contributor Author

yidingww commented Aug 7, 2021

@flavorjones Thank you!!! ❤️

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants