-
Notifications
You must be signed in to change notification settings - Fork 898
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update rubyzip to 2.0.0 #19629
Update rubyzip to 2.0.0 #19629
Conversation
Can you also annotate in the commit that this "Fixes #19622" ? |
@d-m-u I expected to see a line removing |
Can we remove:
|
870e9c7
to
e346761
Compare
@miq-bot add_label security |
@d-m-u Can you squash your commits (cause one of them is pointing to the wrong issue)? |
@d-m-u Also, since this is red due to cross-repo reasons, can you run the cross-repo tests? Also include UI as well |
2a2616f
to
20e2601
Compare
I manually tested the zip logs part of log collection, in addition to the tests on travis so as soon as the other PR is merged and this one gets 💚 , I'll be 👍 |
20e2601
to
4889c8f
Compare
Checked commit d-m-u@4889c8f with ruby 2.5.5, rubocop 0.69.0, haml-lint 0.20.0, and yamllint 1.10.0 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, cross repo is good: ManageIQ/manageiq-cross_repo-tests#37
Will merge when automation is merged.
Merging now that ManageIQ/manageiq-automation_engine#397 is merged |
Update rubyzip to 2.0.0 (cherry picked from commit bc83fb6) https://bugzilla.redhat.com/show_bug.cgi?id=1783403
Hammer backport details:
|
Update rubyzip to 2.0.0 (cherry picked from commit bc83fb6) https://bugzilla.redhat.com/show_bug.cgi?id=1783401
Ivanchuk backport details:
|
We're currently using rubyzip 1.3.0 with "Zip.validate_entry_sizes = true" to address CVE-2019-16892 and should fix it.
Tested the automate side.
@miq-bot assign @jrafanie
Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1781195
Depends on
ManageIQ/manageiq-automation_engine#397
update:
this is Jason:
https://giphy.com/gifs/reactiongifs-bTzmG7ok7Dc6A/tile