Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merge URI-0.12.2 for Bundler #6779

Merged
merged 1 commit into from
Jun 29, 2023
Merged

Merge URI-0.12.2 for Bundler #6779

merged 1 commit into from
Jun 29, 2023

Conversation

hsbt
Copy link
Member

@hsbt hsbt commented Jun 29, 2023

What was the end-user or developer problem that led to this PR?

Our vendored URI is vulnerable version. see https://www.ruby-lang.org/en/news/2023/06/29/redos-in-uri-CVE-2023-36617/

What is your fix for the problem, implemented in this PR?

Update URI-0.12.2.

Make sure the following tasks are checked

@hsbt hsbt enabled auto-merge June 29, 2023 07:20
@hsbt hsbt merged commit a146b28 into master Jun 29, 2023
92 checks passed
@hsbt hsbt deleted the update-uri branch June 29, 2023 08:43
deivid-rodriguez pushed a commit that referenced this pull request Jul 31, 2023
Merge URI-0.12.2 for Bundler

(cherry picked from commit a146b28)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants