thetallgrassnet / pokesite

Your one-stop Pokémon fan community and database
https://thetallgrass.net
GNU Affero General Public License v3.0
1 stars 0 forks source link

🚨 [security] Update ffi: 1.9.18 → 1.9.25 (patch) #331

Open depfu[bot] opened 6 years ago

depfu[bot] commented 6 years ago

🚨 Your version of ffi has known security vulnerabilities 🚨

Advisory: CVE-2018-1000201 Disclosed: June 22, 2018 URL: https://github.com/ffi/ffi/releases/tag/1.9.24

ruby-ffi DDL loading issue on Windows OS

ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be
hijacked on Windows OS, when a Symbol is used as DLL name instead of a String
This vulnerability appears to have been fixed in v1.9.24 and later.


🚨 We recommend to merge and deploy this update as soon as possible! 🚨


We've updated a dependency and here is what you need to know:

name version specification old version new version
ffi indirect dependency 1.9.18 1.9.25

You should probably take a good look at the info here and the test results before merging this pull request, of course.

What changed?

↗️ ffi (indirect, 1.9.18 → 1.9.25) · Repo

Commits

See the full diff on Github. The new version differs by 53 commits:


Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with @depfu rebase.

Depfu Status