Skip to content

chore: upgrade addressable dependency to ~> 2.9#26622

Draft
torreypayne wants to merge 1 commit into
mainfrom
upgrade-addressable
Draft

chore: upgrade addressable dependency to ~> 2.9#26622
torreypayne wants to merge 1 commit into
mainfrom
upgrade-addressable

Conversation

@torreypayne

Copy link
Copy Markdown
Member

Upgrade addressable to ~> 2.9 to mitigate vulnerability GHSA-h27x-rffw-24p4.

Fixes: #26054

Upgrade addressable to ~> 2.9 to mitigate vulnerability GHSA-h27x-rffw-24p4.

Fixes: #26054
@aandreassa

Copy link
Copy Markdown
Contributor

Thanks @torreypayne!

For testing, you can upgrade your addressable gem locally and test it on version 3.2 and 4.0 (using a version manager like asdf).

You can run locally via toys ci --from HEAD~2, or similar if more than 1 commit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Installed version of addressable is vulnerable

2 participants