8000 # bump rubyzip to 1.2.1, to address traversal CVE (rubyzip/rubyzip#315) · NHSDigital/ndr_import@c84ea01 · GitHub
[go: up one dir, main page]

Skip to content

Commit c84ea01

Browse files
Josh PencheonJosh Pencheon
authored andcommitted
# bump rubyzip to 1.2.1, to address traversal CVE (rubyzip/rubyzip#315)
1 parent b1c7383 commit c84ea01

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

code_safety.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -175,7 +175,7 @@ file safety:
175175
ndr_import.gemspec:
176176
comments:
177177
reviewed_by: josh.pencheon
178-
safe_revision: 53cc0af4321b64746367231b65821fda0f8d8a0a
178+
safe_revision: 9ce125b717abc3cc9b8f360ccf1651eef14212d4
179179
test/file/base_test.rb:
180180
comments:
181181
reviewed_by: timgentry

ndr_import.gemspec

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ Gem::Specification.new do |spec|
2222
spec.add_dependency 'activesupport', '>= 3.2.18', '< 5.1'
2323
spec.add_dependency 'ndr_support', '>= 4.1.2', '< 6'
2424

25-
spec.add_dependency 'rubyzip', '~> 1.1'
25+
spec.add_dependency 'rubyzip', '~> 1.2', '>= 1.2.1'
2626
spec.add_dependency 'roo', '~> 2.0'
2727

2828
spec.add_dependency 'nokogiri', '~> 1.6'

0 commit comments

Comments
 (0)
0