Skip to content

fix: ensure rubygems url is using https#1854

Merged
jmeridth merged 1 commit intomasterfrom
jm_change_rubygems_url_in_gemfile_to_https
Aug 6, 2024
Merged

fix: ensure rubygems url is using https#1854
jmeridth merged 1 commit intomasterfrom
jm_change_rubygems_url_in_gemfile_to_https

Conversation

@jmeridth
Copy link
Copy Markdown
Contributor

@jmeridth jmeridth commented Aug 6, 2024

Fixes Dependency source URL uses the unencrypted protocol HTTP. Use HTTPS instead.

Fixes https://github.com/github/markup/security/code-scanning/1

`Dependency source URL uses the unencrypted protocol HTTP. Use HTTPS instead.`

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth jmeridth self-assigned this Aug 6, 2024
@jmeridth jmeridth requested review from kenyonj and zkoppert August 6, 2024 20:07
Copy link
Copy Markdown
Contributor

@kenyonj kenyonj left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:shipit:

@jmeridth jmeridth merged commit c6beb4f into master Aug 6, 2024
@jmeridth jmeridth deleted the jm_change_rubygems_url_in_gemfile_to_https branch August 6, 2024 20:16
zkoppert added a commit that referenced this pull request May 5, 2026
- Add missing security fixes: RubyGems HTTPS (#1854), CI permissions (#1855), rexml bumps
- Add missing community PRs: spelling fixes (#1479), Textile link (#1703)
- Clarify linguist version bump history
- Add Dependabot CI action bumps catch-all entry
- Pin actions/stale to commit SHA for supply chain hardening

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Zack Koppert <zkoppert@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants