Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BILL-19467] Update activesupport to fix CVE #106

Merged
merged 1 commit into from
Nov 9, 2023
Merged

Conversation

kevinchen234
Copy link
Contributor

  • bundle update --conservative activesupport

Description

Snyk issue: https://app.snyk.io/org/growth-and-monetization/project/b6817ceb-01d3-41fa-889b-ec04a1fd6fb4#issue-SNYK-RUBY-ACTIVESUPPORT-5851458

Need to update ActiveSupport gem before the vulnerability goes outside of SLA.

Fix: bundle update --conservative activesupport

JIRA: https://zendesk.atlassian.net/browse/BILL-19467

Risks

Low: Gem Bump

- `bundle update --conservative activesupport`
@kevinchen234 kevinchen234 requested a review from a team as a code owner November 9, 2023 19:02
@kevinchen234 kevinchen234 merged commit f3f4a39 into main Nov 9, 2023
@kevinchen234 kevinchen234 deleted the yuchen/BILL-19467 branch November 9, 2023 19:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants