Skip to content

Conversation

@ScotterC
Copy link
Owner

This fixes CVE-2025-68696 (GHSA-hm5p-x4rq-38w4) by allowing projects to update to httparty 0.24.0 which patches a potential SSRF vulnerability that could lead to API key leakage.

@ScotterC ScotterC force-pushed the sc/relax-httparty-constraint branch 2 times, most recently from 44ad573 to f5562c9 Compare January 12, 2026 16:28
This fixes CVE-2025-68696 (GHSA-hm5p-x4rq-38w4) by allowing projects
to update to httparty 0.24.0 which patches a potential SSRF
vulnerability that could lead to API key leakage.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@ScotterC ScotterC force-pushed the sc/relax-httparty-constraint branch from f5562c9 to 8ea1d6f Compare January 12, 2026 16:31
@ScotterC ScotterC merged commit 18150df into main Jan 12, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants