[Security] Bump ffi from 1.9.23 to 1.9.25 #418
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps ffi from 1.9.23 to 1.9.25. This update includes security fixes.
Vulnerabilities fixed
Sourced from The GitHub Vulnerability Alert Database.
Changelog
Sourced from ffi's changelog.
Commits
aa1b844
Prepare for release 1.9.25f1385ae
Revert "README: Remove now unnecessary PaX workaround [ci skip]"94441aa
Revert "Do closures via libffi"4e1051a
Run rspec with dots output onlye70b13d
Fix integer parameter range specs55ae232
Fix several specs where raise_error was called without class8821d4f
Specify error class for several raise_error callsbf48d44
Fix missing C declarations causing compiler warningsf569788
Replace symlinks for mips r6 with plain filesfedbae0
Update CHANGELOGLooks like TimeOverflow isn't vulnerable in production here (the gem is a subdependency of selenium-webdriver), but still best practice and will silence any GitHub alerts you're getting.