Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in Rouge 2.0.7 #21192

Open
4 tasks done
dvelopmberg opened this issue Apr 12, 2023 · 4 comments
Open
4 tasks done

Vulnerability in Rouge 2.0.7 #21192

dvelopmberg opened this issue Apr 12, 2023 · 4 comments

Comments

@dvelopmberg
Copy link

New Issue Checklist

Issue Description

The fastlane release 2.212.1 is conusming xcpretty 0.3.0
https://github.com/fastlane/fastlane/blob/master/Gemfile.lock

xcpretty 0.3.0 is conusming rouge 2.0.7 and this version has vulnerabilities
https://ossindex.sonatype.org/vulnerability/sonatype-2021-4771?component-type=gem&component-name=rouge&utm_source=dependency-track&utm_medium=integration&utm_content=v4.5.0

I don't know what to do, because the xcpretty project is dead i think? There are no changes since 2018
and the active pull request with the update of rouge is open since end of 2022
xcpretty/xcpretty#383

Command executed

Not relevant.

Complete output when running fastlane, including the stack trace and command used
 Not relevant 

Environment

 Not relevant 
@fastlane-bot
Copy link

It seems like you have not included the output of fastlane env
To make it easier for us help you resolve this issue, please update the issue to include the output of fastlane env 👍

@lolezy
Copy link

lolezy commented Nov 10, 2023

issue still valid on the latest version

@DevMobileAS
Copy link

See xcpretty/xcpretty#383 (comment)
Please fix this!

@DevMobileAS
Copy link

FYI: xcpretty is now at 0.4.0 containing the needed update for rouge to fix the vulnerability.

I'm not sure what exactly I need to update within fastlane to just use the new xcpretty version, but maybe some of the existing contributors could help with this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants