Skip to content

actionview-4.2.10 security vulnerability in Gemfile.lock #17

Closed
@omsai

Description

@omsai

Security e-mail from GitHub:

On Thu, Mar 14, 2019 at 5:07 AM GitHub notifications@github.com wrote:
--snip--
Known critical severity security vulnerability detected in
actionview >= 4.0.0, < 4.2.11.1 defined in Gemfile.lock.
--
Gemfile.lock update suggested: actionview ~> 4.2.11.1.

We can't correct the fault in our Gemfile.lock because the actionview dependency is pulled by version pinning of GitHub pages itself.

I've submitted a pull request upstream:
github/pages-gem#630

After upstream merges the change one should be able to resolve the issue one our end with the same procedure as #1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions