Closed bkabrda closed 4 years ago
Upgrade rake dependency to prevent CVE-2020-8130
https://github.com/advisories/GHSA-jppv-gw3r-w3q8
changelog/
backward-incompatible
do-not-merge/
kind/
severity/
After some evaluation, I'm going to close this. The CVE doesn't hit our users as rake is only a test dependency and it seems that nobody could misuse this in our CI pipeline.
What does this PR do?
Upgrade rake dependency to prevent CVE-2020-8130
https://github.com/advisories/GHSA-jppv-gw3r-w3q8
Description of the Change
Alternate Designs
Possible Drawbacks
Verification Process
Additional Notes
Release Notes
Review checklist (to be filled by reviewers)
changelog/
label attached. If applicable it should have thebackward-incompatible
label attached.do-not-merge/
label attached.kind/
andseverity/
labels attached at least.