Skip to content
This repository has been archived by the owner on Jun 5, 2023. It is now read-only.

Bump rubyzip from 1.2.1 to 1.3.0 #232

Closed
brad-lewis opened this issue Jan 29, 2020 · 3 comments
Closed

Bump rubyzip from 1.2.1 to 1.3.0 #232

brad-lewis opened this issue Jan 29, 2020 · 3 comments

Comments

@brad-lewis
Copy link

Automated security updates showed these alerts:

Dependency      Version                Upgrade to
rubyzip               Version<= 1.2.1   ~> 1.2.2

Vulnerabilities
CVE-2019-16892 High severity
CVE-2018-1000544 Moderate severity

Could we bump to 1.3.0?

@repeatedly
Copy link
Contributor

repeatedly commented Jan 29, 2020

This will be fixed in td-agent 3.6.0.
Of course, you know fluentd itself doesn't use rubyzip.

@brad-lewis
Copy link
Author

brad-lewis commented Jan 29, 2020

I would have thought the way to fix it, is to edit Gemfile.lock

-    rubyzip (1.2.1)
+    rubyzip (1.3.0)

I didn't see that address in the 3.6.0 pull request. Does something else imply a newer version?

@repeatedly
Copy link
Contributor

td-agent 3.5.1 has already installed rubyzip 2.0.0, not 1.2.1.
See #233 (comment)

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants