Skip to content
This repository was archived by the owner on Sep 28, 2021. It is now read-only.

Conversation

@whunter
Copy link
Member

@whunter whunter commented Aug 12, 2019

Update gems to address security issues.


JIRA Ticket: (https://webapps.es.vt.edu/jira/browse/LIBTD-1869) (:star:)

What does this Pull Request do? (:star:)

Update gems to address security issues.

What's the changes? (:star:)

  • Update gems to address security issues.

How should this be tested?

  • set ruby_version: '2.4' in Installscripts/ansible/site_secrets.yml
  • Build gem_updates branch and ensure that application is still functional

Additional Notes:

  • branch gem_updates

Interested parties

@pmather

(:star:) Required fields

override

devise
@whunter whunter requested a review from pmather August 12, 2019 15:05
Copy link
Collaborator

@pmather pmather left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks like more than just an update of the gems currently flagged as having security vulnerabilities (actionview, mini_magick, devise, and bootstrap-sass). It includes an update of Hyrax to 2.2. You should be more explicit about this in the commit/PR message. (In the past, we've just done conservative updates for vulnerable gems, e.g., something along the lines of bundle update actionview mini_magick devise bootstrap-sass which will minimally update the affected gems and associated dependencies. It's not clear in that context why an update of the hyrax gem was necessary.)

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants