Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve Hakiri warning for Sinatra version #15

Merged
merged 1 commit into from
Sep 9, 2019

Conversation

Cruikshanks
Copy link
Member

Because in the previous version of the gemspec we had an open reference to Sinatra it meant we were essentially saying any version would do.

Hakiri was flagging this with CVE-2018-7212, the resolution of which was to specify a version equal to or greater than 2.0.1

@Cruikshanks Cruikshanks added the housekeeping Changes such as refactoring label Sep 9, 2019
@Cruikshanks Cruikshanks self-assigned this Sep 9, 2019
Because in the previous version of the gemspec we had an open reference to Sinatra it meant we were essentially saying any version would do.

Hakiri was flagging this with [CVE-2018-7212](sinatra/sinatra#1379), the resolution of which was to specify a version equal to or greater than 2.0.1

It was then flagging this project with [CVE-2018-11627](sinatra/sinatra#1428), and again the resolution was to specify a version, this time equal to or greater than 2.0.2
@Cruikshanks Cruikshanks merged commit 808bb7a into master Sep 9, 2019
@Cruikshanks Cruikshanks deleted the resolve-sinatra-hakiri-warning branch September 9, 2019 22:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
housekeeping Changes such as refactoring
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant