<#132 Vulnerability in rack 2.2.8, openssl 3.1.0> ...
# pact-ruby-standalone
g
#132 Vulnerability in rack 2.2.8, openssl 3.1.0 Issue created by milda-a Pre issue-raising checklist I have already (please mark the applicable with an
x
): ☑︎ Upgraded to the latest version of the relevant libraries ☑︎ Checked to see if the issue has already been raised ☐ Created an executable example that demonstrates the issue using either: • a Dockerfile • a fork of https://github.com/pact-foundation/pact-ruby-standalone-e2e-example • a Git repository with a Travis or Appveyor (or similar) build • a gist with all the relevant code and full instructions on how to run it N/A Software versions • pact-ruby-standalone: eg 2.4.1 Expected behaviour Vulnerabilities fixed by updating the used rack version. Current version: 2.2.8 Versions with fix: 2.2.8.1, 3.0.9.1 Vulnerabilities fixed by updating the used openssl version. Current version 3.1.0 Versions with fix: 3.1.5, 3.2.1 Actual behaviour High vulnerabilities raised in /home/builder/deps/pact/lib/vendor/ruby/3.2.0/specifications/rack-2.2.8.gemspec Warn vulnerabilities raised in /home/builder/deps/pact/lib/ruby/lib/ruby/gems/3.2.0/specifications/default/openssl-3.1.0.gemspec Steps to reproduce Run software as normal. Vulnerabilities spotted through internal image scanning which includes the pact standalone binaries. pact-foundation/pact-ruby-standalone