Skip to content

[pull] master from ruby:master#852

Merged
pull[bot] merged 1 commit intoturkdevops:masterfrom
ruby:master
Mar 16, 2026
Merged

[pull] master from ruby:master#852
pull[bot] merged 1 commit intoturkdevops:masterfrom
ruby:master

Conversation

@pull
Copy link

@pull pull bot commented Mar 16, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

There are two CVEs in Guava, which is a test-scoped dependency of
this library. Guava is not shipped with the library so these CVEs
do not affect users, but the dependency may trigger security tools.
We update to avoid this false positive.

https://www.cve.org/CVERecord?id=CVE-2023-2976

https://www.cve.org/CVERecord?id=CVE-2020-8908

Fixes ruby/psych#780

ruby/psych@599f89d0fd
@pull pull bot locked and limited conversation to collaborators Mar 16, 2026
@pull pull bot added the ⤵️ pull label Mar 16, 2026
@pull pull bot merged commit 8da2777 into turkdevops:master Mar 16, 2026
1 of 2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant