Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump yard version #2551

Closed
wants to merge 1 commit into from
Closed

Bump yard version #2551

wants to merge 1 commit into from

Conversation

stefannibrasil
Copy link
Contributor

CI is failing due to this CVE:

ruby-advisory-db:
  advisories:	878 advisories
  last updated:	2024-03-13 17:35:01 -0700
  commit:	ff710b9dff3b17cabad830a8011f49b9fa14ec81
Name: yard
Version: 0.9.35
CVE: CVE-2024-27285
GHSA: GHSA-8mq4-9jjh-9xrc
Criticality: Medium
URL: https://github.com/advisories/GHSA-8mq4-9jjh-9xrc
Title: YARD's default template vulnerable to Cross-site Scripting in generated frames.html
Solution: upgrade to '>= 0.9.36'

CI is failing due to this CVE:

```
ruby-advisory-db:
  advisories:	878 advisories
  last updated:	2024-03-13 17:35:01 -0700
  commit:	ff710b9dff3b17cabad830a8011f49b9fa14ec81
Name: yard
Version: 0.9.35
CVE: CVE-2024-27285
GHSA: GHSA-8mq4-9jjh-9xrc
Criticality: Medium
URL: GHSA-8mq4-9jjh-9xrc
Title: YARD's default template vulnerable to Cross-site Scripting in generated frames.html
Solution: upgrade to '>= 0.9.36'
```
@nickcharlton
Copy link
Member

Ah, sorry, I was going through my notifications in reverse and didn't see this. I've merged in a Yard upgrade in #2540.

@stefannibrasil stefannibrasil deleted the sb-bump-yard branch March 18, 2024 15:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants