Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

mini_magick dependency contains security vulnerability #15044

Closed
johngun3 opened this issue Jul 18, 2019 · 3 comments
Closed

mini_magick dependency contains security vulnerability #15044

johngun3 opened this issue Jul 18, 2019 · 3 comments

Comments

@johngun3
Copy link

johngun3 commented Jul 18, 2019

Feature Request

The mini_magick gem has a security vulnerability for versions less than 4.9.4. The current version used by fastlane is 4.5.1. https://nvd.nist.gov/vuln/detail/CVE-2019-13574

Motivation Behind Feature

Github is notifying projects that contain security vulnerabilities via email and on push so my organization continues to get notified about this vulnerability. Upgrading the version of this gem to one that does not contain a known vulnerability will make the notifications go away.

@janpio
Copy link
Member

janpio commented Jul 18, 2019

Already done, PR is merged: #15042
Release will follow soon.

Thanks for reporting!

(Keeping this issue open until the release is out so we don't get many more of this.)

@johngun3
Copy link
Author

Just curious, how soon is soon for the release?

@KrauseFx
Copy link
Member

Thanks everyone, this seems to have been shipped now 🚀 #15042 (comment)

@fastlane fastlane locked and limited conversation to collaborators Sep 19, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants