Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Bump ruby-openid from 2.8.0 to 2.9.1 #6789

Merged
merged 1 commit into from
Jan 2, 2020

Conversation

dependabot-preview[bot]
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Nov 17, 2019

Bumps ruby-openid from 2.8.0 to 2.9.1. This update includes a security fix.

Vulnerabilities fixed

Sourced from The Ruby Advisory Database.

ruby-openid SSRF via claimed_id request
Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable
flaw. This library is used by Rails web applications to integrate with OpenID Providers.
Severity can range from medium to critical, depending on how a web application developer
chose to employ the ruby-openid library. Developers who based their OpenID integration
heavily on the "example app" provided by the project are at highest risk.

Patched versions: >= 2.9.0
Unaffected versions: none

Release notes

Sourced from ruby-openid's releases.

v2.9.1

Update CHANGELOG with all the changes in v2.9.0
and update version.rb

v2.9.0

  • Remove deprecated autorequire from gemspec.
    #123
  • Rescue from Yadis::XRI::XRIHTTPError on discovery.
    #106
  • Avoid SSRF for claimed_id request.
    #121
  • Updated documentation.
    #115, #116, #117, #118
  • Reduce warnings output in test runs.
    #119
  • Drop deprecated option from gemspec.
    #120
  • Remove circular require.
    #113
  • Updated Travis CI config with Ruby 2.6
    #114
  • Simplify Bundler require; remove need for extra :require.
    #112
Changelog

Sourced from ruby-openid's changelog.

2.9.1

  • Updated CHANGELOG.md

2.9.0

  • Remove deprecated autorequire from gemspec.
    #123
  • Rescue from Yadis::XRI::XRIHTTPError on discovery.
    #106
  • Avoid SSRF for claimed_id request.
    #121
  • Updated documentation.
    #115, #116, #117, #118
  • Reduce warnings output in test runs.
    #119
  • Drop deprecated option from gemspec.
    #120
  • Remove circular require.
    #113
  • Updated Travis CI config with Ruby 2.6
    #114
  • Simplify Bundler require; remove need for extra :require.
    #112
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yml file in this repo:

  • Update frequency
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file Ruby security labels Nov 17, 2019
@dependabot-preview dependabot-preview bot force-pushed the dependabot/bundler/ruby-openid-2.9.1 branch from 512d74a to 6429f35 Compare November 27, 2019 20:23
@dependabot-preview dependabot-preview bot force-pushed the dependabot/bundler/ruby-openid-2.9.1 branch 3 times, most recently from 7da7849 to 4f69ecf Compare December 17, 2019 17:40
Bumps [ruby-openid](https://github.com/openid/ruby-openid) from 2.8.0 to 2.9.1. **This update includes a security fix.**
- [Release notes](https://github.com/openid/ruby-openid/releases)
- [Changelog](https://github.com/openid/ruby-openid/blob/master/CHANGELOG.md)
- [Commits](openid/ruby-openid@v2.8.0...v2.9.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot force-pushed the dependabot/bundler/ruby-openid-2.9.1 branch from 4f69ecf to 13e3cf2 Compare January 2, 2020 21:55
@codecov
Copy link

codecov bot commented Jan 2, 2020

Codecov Report

Merging #6789 into master will increase coverage by 0.04%.
The diff coverage is 100%.

Impacted file tree graph

@@            Coverage Diff             @@
##           master    #6789      +/-   ##
==========================================
+ Coverage   80.64%   80.68%   +0.04%     
==========================================
  Files          97       97              
  Lines        5565     5567       +2     
==========================================
+ Hits         4488     4492       +4     
+ Misses       1077     1075       -2
Impacted Files Coverage Δ
app/controllers/users_controller.rb 80.98% <100%> (+0.84%) ⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 01d5ce6...13e3cf2. Read the comment docs.

@plotsbot
Copy link
Collaborator

plotsbot commented Jan 2, 2020

1 Warning
⚠️ There was an error with Danger bot’s Junit parsing: No JUnit file was found at output.xml
2 Messages
📖 @dependabot-preview[bot] Thank you for your pull request! I’m here to help with some tips and recommendations. Please take a look at the list provided and help us review and accept your contribution! And don’t be discouraged if you see errors – we’re here to help.
📖 #
Screenshots 📸 (click to expand)

6789-test_questions.png

6789-test_embeddable_grids.png

6789-test_signup.png

6789-test_viewing_the_settings_page.png

6789-test_tag_by_author_page.png

6789-test_wiki_page_with_inline_grids.png

6789-test_stats.png

6789-test_viewing_the_dashboard.png

6789-test_searching_an_item_from_the_homepage.png

6789-test_questions_shadow.png

6789-test_login_modal.png

6789-test_profile_page.png

6789-test_comments.png

6789-test_tags.png

6789-test_signup_modal.png

6789-test_wiki.png

6789-test_methods.png

6789-test_tag_page.png

6789-test_blog_page_with_location_modal.png

6789-test_tag_wildcard.png

6789-test_embeddable_thumbnail_grids.png

6789-test_front_page_with_navbar_search_autocomplete.png

6789-test_login.png

6789-test_viewing_the_dropdown_menu.png

6789-test_viewing_question_post.png

6789-test_mobile_displays.png

6789-test_simple-data-grapher_powertag.png

6789-test_front.png

6789-test_question_page.png

6789-test_tag_contributors_page.png

6789-test_blog.png

6789-test_people.png

6789-test_wiki_revisions.png

Learn about automated screenshots

Generated by 🚫 Danger

@jywarren
Copy link
Member

jywarren commented Jan 2, 2020

I would merge this but I'm afraid of the drop in coverage... I think it's an artifact though, as noting in #6290

@jywarren jywarren merged commit 44037c3 into master Jan 2, 2020
@dependabot-preview dependabot-preview bot deleted the dependabot/bundler/ruby-openid-2.9.1 branch January 2, 2020 22:41
Tlazypanda pushed a commit to Tlazypanda/plots2 that referenced this pull request Jan 14, 2020
Bumps [ruby-openid](https://github.com/openid/ruby-openid) from 2.8.0 to 2.9.1. **This update includes a security fix.**
- [Release notes](https://github.com/openid/ruby-openid/releases)
- [Changelog](https://github.com/openid/ruby-openid/blob/master/CHANGELOG.md)
- [Commits](openid/ruby-openid@v2.8.0...v2.9.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
vinitshahdeo pushed a commit to vinitshahdeo/plots2 that referenced this pull request Feb 1, 2020
Bumps [ruby-openid](https://github.com/openid/ruby-openid) from 2.8.0 to 2.9.1. **This update includes a security fix.**
- [Release notes](https://github.com/openid/ruby-openid/releases)
- [Changelog](https://github.com/openid/ruby-openid/blob/master/CHANGELOG.md)
- [Commits](openid/ruby-openid@v2.8.0...v2.9.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file Ruby security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants