sonatype-nexus-community / chelsea

Dependency vulnerability auditor for Ruby
Apache License 2.0
14 stars 11 forks source link

fix CVE-2021-28965 via rubocop (direct dependency) upgrade. document it #44

Closed bhamail closed 3 years ago

bhamail commented 3 years ago

IQ Server discovered a vulnerability in one of our components.

I upgraded the vulnerable component, and left a trail of bread crumbs through the forest.

Please holler if I've suggested anything horrific.

cc @bhamail / @DarthHater / @brittanybelle / @gmohre

DarthHater commented 3 years ago

@bhamail I sent this to @lomky and @colinxfleming, who are both Ruby veterans and awesome people (who I think you remember), you might get some feedback from them!

bhamail commented 3 years ago

@lomky I made the big long bundle output text collapsed by default. Hopefully that is better (I kinda wanted to keep the details of the different approaches available for the morbidly curious).

Screen Shot 2021-04-12 at 4 56 32 PM
colinxfleming commented 3 years ago

Good explanation of the moving pieces here I think, and covers viable approaches - looks good to my eyes, whatever that's worth!