Skip to content

Commit 88f8aed

Browse files
authored
Merge pull request #626 from Fryguy/bump_rack
Bump rack to 3.1.20 for CVE-2026-22860
2 parents 9e8766b + c319c21 commit 88f8aed

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

manageiq-gems-pending.gemspec

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -42,8 +42,7 @@ Gem::Specification.new do |s|
4242

4343
s.add_development_dependency "ftpd", "~> 2.1.0"
4444
s.add_development_dependency "manageiq-style", ">= 1.5.4"
45-
46-
s.add_development_dependency "rack", "~> 3.1.19" # this ensures manageiq-style's rack requirement is safe CVE-2025-61919 https://github.com/advisories/GHSA-6xw4-3v39-52mm
45+
s.add_development_dependency "rack", "~> 3.1.20" # transitive dependency of manageiq-style CVE-2026-22860 https://github.com/advisories/GHSA-mxw3-3hh2-x2mh
4746
s.add_development_dependency "rake", ">= 12.3.3"
4847
s.add_development_dependency "rspec", "~> 3.13"
4948
s.add_development_dependency "simplecov", ">= 0.21.2"

0 commit comments

Comments
 (0)