Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update rubyzip from 1.2.1 to 1.3.0 #515

Merged
merged 2 commits into from
Jan 8, 2020
Merged

Update rubyzip from 1.2.1 to 1.3.0 #515

merged 2 commits into from
Jan 8, 2020

Conversation

Kevinrob
Copy link
Contributor

@Kevinrob Kevinrob commented Oct 2, 2019

Summary

Updated rubyzip version. Now minimal version is 1.3.0. CVE-2019-16892

@coveralls
Copy link

coveralls commented Oct 2, 2019

Coverage Status

Coverage increased (+0.04%) to 94.404% when pulling 22b5c3a on Kevinrob:rubyzip_CVE-2019-16892 into 4ec1104 on roo-rb:master.

@coveralls
Copy link

Coverage Status

Coverage increased (+0.04%) to 94.408% when pulling 09bf80e on Kevinrob:rubyzip_CVE-2019-16892 into 4ec1104 on roo-rb:master.

@ansonhoyt
Copy link

What do you think about also loosening the maximum version to allow rubyzip 2.0.0, which just came out 2019-09-25?

The rubyzip changelog covers the breaking changes. I'm not a roo expert, but they don't sound like things that would break roo itself.

Curious what you (more knowledgeable) folks think about loosening the dependency.

@Kevinrob
Copy link
Contributor Author

Kevinrob commented Oct 7, 2019

@ansonhoyt Yeah, that's right! I will update the PR

@manuelmeurer
Copy link

Would love to see this merged to be able to use RubyZip 2.0!

@daande
Copy link

daande commented Dec 4, 2019

@Kevinrob Can we get this merged? As prior to ruby-zip 1.3.0 there is the following vulnerability: https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubyzip/CVE-2019-16892.yml

@ahukkanen
Copy link

Definitely needed as other external dependencies are updating to rubyzip 2.0+.

@Kevinrob
Copy link
Contributor Author

Kevinrob commented Dec 5, 2019

@Kevinrob Can we get this merged? As prior to ruby-zip 1.3.0 there is the following vulnerability: https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubyzip/CVE-2019-16892.yml

Of course we can. But I don't have write access to this repo 😜

@daande
Copy link

daande commented Jan 8, 2020

@Empact @stevendaniels @simonoff @chopraanmol1 @rlburkes @tpickett66 @pabloh @FestivalBobcats Can one of you merge this or get it merged please?

@chopraanmol1 chopraanmol1 merged commit 221750b into roo-rb:master Jan 8, 2020
@daande
Copy link

daande commented Jan 8, 2020

@chopraanmol1 Thank you!

@manuelmeurer
Copy link

manuelmeurer commented Jan 9, 2020

@chopraanmol1 Could you please release a new version of this gem as well?

@daande
Copy link

daande commented Jan 13, 2020

@chopraanmol1 Could you please release a new version of this gem as well?

I will send @chopraanmol1 an email trying to get a new release

@uri-ravzin
Copy link

would love to get a new version here as well !
especially allowing rubyzip over 2.0.0

@chopraanmol1
Copy link
Member

Will try my best to release on the weekend. If I'm unable to release on the weekend will surely release by next week

@jspanjers
Copy link

@chopraanmol, would love to have a new version!

@chopraanmol1
Copy link
Member

Sorry for the delay. I've released v2.8.3

@jspanjers
Copy link

Thanks!

netbsd-srcmastr pushed a commit to NetBSD/pkgsrc that referenced this pull request Mar 8, 2020
Update ruby-roo to 2.8.3.


##  [2.8.3] 2020-02-03
### Changed/Added
- Updated rubyzip version. Now minimal version is 1.3.0 [515](roo-rb/roo#515) - [CVE-2019-16892](rubyzip/rubyzip#403)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

9 participants