Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump middleman dep #58

Merged
merged 1 commit into from Jul 11, 2018
Merged

bump middleman dep #58

merged 1 commit into from Jul 11, 2018

Conversation

dschobel
Copy link
Contributor

One of middleman's transitive deps (sprockets 2.12.4) has a known security vulnerability so we bump middleman to a version which doesn't have the issue.

Known vulnerability found
CVE-2018-3760
High severity
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's ...

Gemfile.lock update suggested:
sprockets ~> 2.12.5
Always verify the validity and compatibility of suggestions with your codebase.

Copy link
Collaborator

@bryce-anderson bryce-anderson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Presuming it still builds.

@dschobel dschobel merged commit 9b88b87 into finagle:source Jul 11, 2018
@cacoco
Copy link
Contributor

cacoco commented Jul 11, 2018

Can you try to run the blog locally with these changes? Just to make sure.

@dschobel
Copy link
Contributor Author

I tested it locally and it rendered fine. It failed in travisci because we need to bump the ruby version: https://travis-ci.org/finagle/finagle.github.io/jobs/402802163

@dschobel
Copy link
Contributor Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants