Skip to content

Bump faraday to 2.14.2 for security advisory#38

Merged
martijnversluis merged 1 commit into
mainfrom
bump-faraday-for-cve
May 27, 2026
Merged

Bump faraday to 2.14.2 for security advisory#38
martijnversluis merged 1 commit into
mainfrom
bump-faraday-for-cve

Conversation

@martijnversluis

Copy link
Copy Markdown
Contributor

Adresseert de open Dependabot alert:

  • faraday <= 2.14.1 (low) — incomplete fix voor host-scoping bypass via protocol-relative URI's (GHSA-33mh-2634-fwr2).

Tests groen (42 examples).

@martijnversluis martijnversluis merged commit 3c3ebc4 into main May 27, 2026
1 check passed
@martijnversluis martijnversluis deleted the bump-faraday-for-cve branch May 27, 2026 06:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant