DataDog / dogapi-rb

Ruby client for Datadog's API
https://www.datadoghq.com
BSD 3-Clause "New" or "Revised" License
96 stars 88 forks source link

Upgrade rake dependency to prevent CVE-2020-8130 #225

Closed bkabrda closed 4 years ago

bkabrda commented 4 years ago

What does this PR do?

Upgrade rake dependency to prevent CVE-2020-8130

https://github.com/advisories/GHSA-jppv-gw3r-w3q8

Description of the Change

Alternate Designs

Possible Drawbacks

Verification Process

Additional Notes

Release Notes

Review checklist (to be filled by reviewers)

bkabrda commented 4 years ago

After some evaluation, I'm going to close this. The CVE doesn't hit our users as rake is only a test dependency and it seems that nobody could misuse this in our CI pipeline.