Project

General

Profile

Actions

Bug #20667

closed

Backport REXML CVE fixes

Added by vo.x (Vit Ondruch) 4 months ago. Updated 3 months ago.

Status:
Closed
Assignee:
-
Target version:
-
ruby -v:
ruby 3.3.4 (2024-07-09 revision be1089c8ec) [x86_64-linux]
[ruby-core:118796]

Description

It would be nice to have the recent REXML CVE fixes backported everywhere.

BTW it is surprising that REXML was recently bumped in 3.1 / 3.2 branches, but 3.3 branch stays with older REXML 3.2.

Actions #1

Updated by hsbt (Hiroshi SHIBATA) 4 months ago

  • Status changed from Open to Closed
  • Backport changed from 3.1: UNKNOWN, 3.2: UNKNOWN, 3.3: UNKNOWN to 3.1: REQUIRED, 3.2: REQUIRED, 3.3: REQUIRED
Actions #2

Updated by kou (Kouhei Sutou) 4 months ago

  • Subject changed from Backport ReXML CVE fixes to Backport REXML CVE fixes
  • Description updated (diff)

Updated by nagachika (Tomoyuki Chikanaga) 4 months ago

  • Backport changed from 3.1: REQUIRED, 3.2: REQUIRED, 3.3: REQUIRED to 3.1: REQUIRED, 3.2: DONE, 3.3: REQUIRED

Updated by k0kubun (Takashi Kokubun) 3 months ago

  • Backport changed from 3.1: REQUIRED, 3.2: DONE, 3.3: REQUIRED to 3.1: REQUIRED, 3.2: DONE, 3.3: DONE

Updated by k0kubun (Takashi Kokubun) 3 months ago

Please consider filing a backport PR to stable branches next time.

Updated by hsbt (Hiroshi SHIBATA) 3 months ago

  • Backport changed from 3.1: REQUIRED, 3.2: DONE, 3.3: DONE to 3.1: DONE, 3.2: DONE, 3.3: DONE
Actions

Also available in: Atom PDF

Like0
Like0Like0Like0Like0Like0Like0