-
Notifications
You must be signed in to change notification settings - Fork 2.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade rexml to 3.3.8 to fix CVE-2024-43398 #5245
Conversation
Hey @aenand could you help with the review with this? |
Absolutely! Thank you for raising this. I'll review it today |
This looks good to me from a changelog perspective. @Buitragox is performing some more in depth testing to see if the latest available version (3.3.7) works |
Thanks @aenand . should I bump the version here to |
Yes please bump to 3.3.7 |
Latest version 3.3.7 works fine |
bumped. thanks! @aenand @Buitragox |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you for this! This will get merged next week
there's a new version just came out, https://github.com/ruby/rexml/releases should we update to that since we haven't merged it yet? |
@Buitragox what is your deploy plan? Would you rather retest on the new version or are you planning to merge this soon? |
a66dd38
to
25fc445
Compare
done. thanks @Buitragox |
Resolves CVE-2024-43398
Tests
bundle exec rake test:local