[AutoPR- Security] Patch ruby for CVE-2025-61594 [LOW]#15436
[AutoPR- Security] Patch ruby for CVE-2025-61594 [LOW]#15436kgodara912 merged 3 commits intomicrosoft:3.0-devfrom
Conversation
|
The CVE-2025-61594.patch has been considered from ruby/uri@20157e3 as the uri version in azl 3.0 ruby-3.3.5 is 0.13.1. |
|
Buddy Build link: https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1023027&view=results Buddy Build result is successful |
One missing closing parenthesis in test file (line with |
|
Here is the latest buddy build - https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1029813&view=results |
Latest Buddy build link : https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1029849&view=results Buddy build is successful. |
suresh-thelkar
left a comment
There was a problem hiding this comment.
Thanks for making the code changes. I sign off.
kgodara912
left a comment
There was a problem hiding this comment.
Buddy build is successful. Patch matches with upstream reference. LGTM.
Auto Patch ruby for CVE-2025-61594.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1018930&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology