Skip to content

[Security] Bumped Rack version to 2.2.3.1#1034

Merged
colszowka merged 1 commit intosimplecov-ruby:mainfrom
nhtruong:main
Dec 23, 2022
Merged

[Security] Bumped Rack version to 2.2.3.1#1034
colszowka merged 1 commit intosimplecov-ruby:mainfrom
nhtruong:main

Conversation

@nhtruong
Copy link
Contributor

@nhtruong nhtruong commented Nov 11, 2022

Rack 2.2.3 suffers from 2 CVEs which are fixed in 2.2.3.1:
https://github.com/rack/rack/blob/main/CHANGELOG.md#2231---2022-05-27

Signed-off-by: Theo Truong theotr@amazon.com

Rack 2.2.3 suffers from 2 CVEs which are fixed in 2.2.3.1: https://github.com/rack/rack/blob/main/CHANGELOG.md#2231---2022-05-27

Signed-off-by: Theo Truong <theotr@amazon.com>
@colszowka colszowka merged commit 43f0e39 into simplecov-ruby:main Dec 23, 2022
@colszowka
Copy link
Collaborator

Thanks! Although I think we shouldn't actually have a Gemfile.lock inside the repo for a gem, but my naive attempt at removing it in #1040 didn't pass so we'll revisit that later

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants