boxen / boxen-web

Automate your team's Boxen installations.
http://boxen.github.com
MIT License
208 stars 111 forks source link

Upgrade Rails due to security vulnerabilities (CVE-2016-2097, CVE-2016-2098) #101

Closed hubot closed 7 years ago

hubot commented 7 years ago

Heaven detected that rails is not >= 5.0, ~> 3.2.22.2, ~> 4.1.14.2, ~> 4.2.5.2

Your Gemfile.lock on the master branch currently is 4.2.8.

Can you folks fix this up? :revolving_hearts:

/cc https://github.com/github/security/issues/1468

jacobbednarz commented 7 years ago

cc @oreoshake - Looks like your security checks for rails are a bit behind.

oreoshake commented 7 years ago

We don't use boxen anymore ¯_(ツ)_/¯

jacobbednarz commented 7 years ago

Oh, I understood that much but there are also newer versions of Rails 4.2.x that have mitigated theses CVEs.

oreoshake commented 7 years ago

Ah, I see. Yeah, it's not perfect :smile: