8000 bump rubyzip version to ~>1.2 to fix CVE-2017-5946 by michaelglass · Pull Request #5288 · SeleniumHQ/selenium · GitHub
[go: up one dir, main page]

Skip to content

bump rubyzip version to ~>1.2 to fix CVE-2017-5946 #5288

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

michaelglass
Copy link
Contributor
@michaelglass michaelglass commented Jan 4, 2018

see rubyzip/rubyzip#315

I'm not sure how third_party/jruby dependencies work but that version looks like it still has the vulnerability, albeit I don't think there's a threat vector from those third_party/... gems.

@michaelglass
Copy link
Contributor Author
michaelglass commented Jan 5, 2018

can also use the current version with

gem "selenium-webdriver", git: "https://github.com/noredink/selenium", branch: "3.8.0-with-newer-rubyzip"

@barancev barancev added the C-rb Ruby Bindings label Jan 8, 2018
@p0deje
Copy link
Member
p0deje commented Jan 9, 2018

Thank you, merged in b3cda32!

@p0deje p0deje closed this Jan 9, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
C-rb Ruby Bindings
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants
0