-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update Rails 6.0 to 6.0.4.6 #253
Comments
Hi @vladimir-mencl-eresearch, I have checked our dependabot alerts and we did not receive any alerts for those that you mentioned, However I have fixed up the versioning in #254 and also removed Let me know if there are any other changes you recommend, thanks |
Hi @waldofouche , Thanks, just looking at #254 . I can see that it relaxes the pinning to Not sure why you don't get the dependabot alert - but the version info in GHSA-wh98-p28r-vrc9 marks 6.0.4.4 as vulnerable and 6.0.4.6 as fixing CVE-2022-23633. Cheers, |
Ah sorry about that! I ran our Thanks for catching that! |
Thanks, all good! |
Hi,
I've just pulled in the recent updates (#249) and got to Rails 6.0.4.4 ... but still get a dependabot alert for CVE-2022-23633 / GHSA-wh98-p28r-vrc9 against
actionpack
, because for Rails 6.0, it's only fixed in 6.0.4.6.Not sure whether you already got this alert - if not, might possibly be because the Rails version selector in
Gemfile
explicitly pins it to6.0.4.4
- shouldn't that rather be:?
Just guessing based on prior use ....
Cheers,
Vlad
The text was updated successfully, but these errors were encountered: