Skip to content

Conversation

@hlascelles
Copy link
Contributor

@hlascelles hlascelles commented Dec 16, 2024

The link to whatisthor.com is insecure: http://whatisthor.com/

It should be the secure version.

2024-12-16_15-25

Looks like Google has cached it too:

image

The link to whatisthor.com is insecure. It should be the secure version.
@hlascelles hlascelles changed the title Use secure thor link Use secure whatisthor.com link Dec 16, 2024
@hlascelles
Copy link
Contributor Author

hlascelles commented Mar 24, 2025

@rafaelfranca @yahonda I hope this is a straightforward one? I understand there are talks to drop the website entirely, but in the meantime this should be a no-problem update to present a better face of thor to the world.

@rafaelfranca rafaelfranca merged commit 2bed4d1 into rails:main Jul 18, 2025
8 checks passed
bmwiedemann pushed a commit to bmwiedemann/openSUSE that referenced this pull request Jul 24, 2025
https://build.opensuse.org/request/show/1295381
by user dancermak + dimstar_suse
- 1.4.0:
## What's Changed
* Lazy-load YAML for performance improvement in rails/thor#892
* Fix encoding error when displaying diffs in rails/thor#898
* Fix unsafe shell command construction (security issue) in rails/thor#897 (bsc#1246809)
* Support `git difftool`-style merge tool identifiers in rails/thor#900
* Add `gsub_file!` and make `gsub_file` fail if no substitutions occur in rails/thor#877
## Security
* CVE-2025-54314: Fixed a vulnerability where user input could result in unsafe shell command execution. (bsc#1246809)
## New Contributors
* @hlascelles made their first contribution in rails/thor#893
**Full Changelog**: https://github.com/rail
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants