Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Run bundler-audit on PRs #23514

Merged
merged 2 commits into from Feb 18, 2023
Merged

Run bundler-audit on PRs #23514

merged 2 commits into from Feb 18, 2023

Conversation

nschonni
Copy link
Contributor

Doesn't look like the CodeClimate is really used anymore, so migrating one of the last 2 hooks.
Will push a second commit with the config to fix the failure that should be shown in the first one

@nschonni
Copy link
Contributor Author

The wiki around the mitigation points to this spec test to confirm the mitigation, but I wasn't sure about adding it omniauth/omniauth#809 (comment)

@github-actions
Copy link
Contributor

This pull request has merge conflicts that must be resolved before it can be merged.

@nschonni
Copy link
Contributor Author

Now that Superlinter is replaced, I just added this as a step with the other Ruby linting job

@Gargron
Copy link
Member

Gargron commented Feb 18, 2023

Question, with dependabot and whatnot running on this repository, do we really need bundler-audit?

@nschonni
Copy link
Contributor Author

I think it can serve a slightly different purpose. The one that is suppressed would have had a Dependabot PR opened, but then likely closed for some breaking changes in the major version update. I think you did a workaround according to the described CVE and workaround from the upstream project, so it can then be ignored will the major bump of that dependency can be done later.
I've done limited Ruby, so I haven't done much of the project setup stuff in some time

@Gargron Gargron merged commit de4b822 into mastodon:main Feb 18, 2023
@nschonni nschonni deleted the bundler-audit branch February 18, 2023 16:01
btrd pushed a commit to btrd/mastodon that referenced this pull request Feb 22, 2023
skerit pushed a commit to 11ways/mastodon that referenced this pull request Jul 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants