Skip to content

Commit

Permalink
feat(gitlab-cng-17.3): pending upstream fix GHSA-9hf4-67fc-4vf4 (#8650)
Browse files Browse the repository at this point in the history
Marking as pending upstream fix:

> Due to the affected Gem version being defined inside a Gemfile.lock file, we are unable to determine in the build pipeline a different version for this dependency and must wait for upstream implementation.

This follows on from the same advisory filed for gitlab-cng-17.4 @ #8537

Signed-off-by: philroche <phil.roche@chainguard.dev>
  • Loading branch information
philroche authored Oct 11, 2024
1 parent ef96694 commit 18eec58
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions gitlab-cng-17.3.advisories.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -93,3 +93,7 @@ advisories:
componentType: gem
componentLocation: /usr/lib/ruby/gems/3.2.0/specifications/puma-5.6.8.gemspec
scanner: grype
- timestamp: 2024-10-11T16:24:18Z
type: pending-upstream-fix
data:
note: Due to the affected Gem version being defined inside a Gemfile.lock file, we are unable to determine in the build pipeline a different version for this dependency and must wait for upstream implementation.

0 comments on commit 18eec58

Please sign in to comment.