[Security] Bump ffi from 1.9.23 to 1.9.25 #418
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps ffi from 1.9.23 to 1.9.25. This update includes security fixes.
Vulnerabilities fixed
Sourced from The GitHub Vulnerability Alert Database.
Changelog
Sourced from ffi's changelog.
Commits
aa1b844Prepare for release 1.9.25f1385aeRevert "README: Remove now unnecessary PaX workaround [ci skip]"94441aaRevert "Do closures via libffi"4e1051aRun rspec with dots output onlye70b13dFix integer parameter range specs55ae232Fix several specs where raise_error was called without class8821d4fSpecify error class for several raise_error callsbf48d44Fix missing C declarations causing compiler warningsf569788Replace symlinks for mips r6 with plain filesfedbae0Update CHANGELOGLooks like TimeOverflow isn't vulnerable in production here (the gem is a subdependency of selenium-webdriver), but still best practice and will silence any GitHub alerts you're getting.