-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bundler < 2.2.10 has "Source Priority" vulnerability #1126
Comments
Thanks! |
The use of Bundler 2.1.4 might hide missing |
Thanks @dentarg it looks like that fix is merged. Is it in 2.2.11? I've staged 2.2.11 on main |
@schneems rubygems/rubygems#4297 is in Bundler 2.2.8 according to their release notes: https://github.com/rubygems/rubygems/releases/tag/bundler-v2.2.8 |
Okay, I think it will be much easier to run into the problem (you rely on the I guess there's the risk of apps not starting after the daily dyno cycling?
|
Ahh, so the risk is people were previously relying on People won't get bundler 2.2.11 unless they make a new deploy. In that case we boot the app for Another mitigating factor (for rails apps) is Rails does a blanket |
That's great and good to know 👍🏻 |
* upstream/main: (52 commits) Fix date (heroku#1152) Bundler 2.2.16 (heroku#1150) v226 (heroku#1149) [changelog skip] Remove Heroku-16 from tests: (heroku#1146) [close 1135] Update bundler 2.x to 2.2.15 (heroku#1144) [changelog skip] Clean up mime magic in repos (heroku#1145) Clean up CNB release process (heroku#1139) Use correct method name in script heroku#1129 (heroku#1129) Post-release updates: heroku/ruby 0.1.0 (heroku#1138) Add package.toml (heroku#1137) Add CNB release scripts (heroku#1136) Release v225 (heroku#1133) [close heroku#1126] Update bundler to 2.2.11 (heroku#1132) Update buildpack tests (heroku#1131) v224 (heroku#1128) Use jvm buildpack to install JRuby dependencies (heroku#1119) Fix YAML formatting (heroku#1116) Rails 2, 3, and 4 LTS tests (heroku#1115) v223 (heroku#1114) Fail detection with a CNB-friendly exit code (heroku#1112) ...
AFAICT, this buildpack is currently using bundler 2.1.4 (
BLESSED_BUNDLER_VERSIONS
).I know that a lot of care and thought goes into bundler upgrades. So, I'm not suggesting a specific course of action, but it is a vulnerability that concerns me.
The text was updated successfully, but these errors were encountered: