circleci / circleci-docs

Documentation for CircleCI.
https://circleci.com/docs/
Other
785 stars 1.3k forks source link

Update httparty indirect dependency for CVE-2024-22049 #8858

Closed tfe closed 1 month ago

tfe commented 1 month ago

Description

This gem is depended on by the pronto and gitlab gems, but fortunately both of them aren't too opinionated on the version of httparty, so we can just in-place update that to a non-vulnerable version.

Reasons

https://security.snyk.io/vuln/SNYK-RUBY-HTTPARTY-3188560