18F / micropurchase

18F's micro-purchase threshold experiment management app.
https://micropurchase.18f.gov
Other
68 stars 37 forks source link

Actionmailer security issue #1524

Open stvnrlly opened 7 years ago

stvnrlly commented 7 years ago

Because it relies on a slightly-older version of mail, it looks like actionmailer is susceptible to https://github.com/mikel/mail/pull/1097. The mail gem is already patched, but it hasn't been pulled in yet.

It looks like another fix might be to update Ruby to 2.4.