Skip to content

update bundler to fix issues raised by dependabot:#4

Open
miguelac wants to merge 1 commit into
playpasshq:masterfrom
Telleroo:fix/bundler-security-issues-raised-by-dependabot
Open

update bundler to fix issues raised by dependabot:#4
miguelac wants to merge 1 commit into
playpasshq:masterfrom
Telleroo:fix/bundler-security-issues-raised-by-dependabot

Conversation

@miguelac

@miguelac miguelac commented Sep 6, 2022

Copy link
Copy Markdown
  • Dependency Confusion in Bundler
  • Insecure path handling in Bundler
  • Local Code Execution through Argument Injection via dash leading git
    url parameter in Gemfile.

- Dependency Confusion in Bundler
- Insecure path handling in Bundler
- Local Code Execution through Argument Injection via dash leading git
  url parameter in Gemfile.
-
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant