Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Bump omniauth from 1.3.1 to 1.4.2 #313

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot-preview[bot]
Copy link

Bumps omniauth from 1.3.1 to 1.4.2. This update includes security fixes.

Vulnerabilities fixed

omniauth leaks authenticity token in callback params
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.

Patched versions: [">= 1.3.2"]
Unaffected versions: []

Release notes

Sourced from omniauth's releases.

v1.4.2

Fixes

  • Mitigate Hashie regressions
Commits
  • 9897127 Bump version to 1.4.2
  • 6abedb0 Merge pull request #880 from omniauth/hashie
  • df7699d Temporary Hashie Regression Fix
  • 2dccbb5 Bump version to 1.4.1
  • 3c0f586 Merge pull request #878 from omniauth/dependency-updates
  • c299e30 Gem updates CI tests
  • 949ffca Bump version to 1.4.0
  • 0edc7ec Merge pull request #874 from michaelherold/silence-mash-logger
  • 00481a9 Silence Hashie::Mash logger on Hashie 3.5.0+
  • cb82bb4 Merge pull request #876 from omniauth/secure-asset-url
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot ignore this [minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use [this|these] label[s] will set the current labels as the default for future PRs for this repo and language

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)

Finally, you can contact us by mentioning @dependabot.

Bumps [omniauth](https://github.com/omniauth/omniauth) from 1.3.1 to 1.4.2. **This update includes security fixes.**
- [Release notes](https://github.com/omniauth/omniauth/releases)
- [Commits](omniauth/omniauth@v1.3.1...v1.4.2)

Signed-off-by: dependabot[bot] <support@dependabot.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant