GitHub
02/27/2024, 1:20 PMx):
☑︎ Upgraded to the latest version of the relevant libraries
☑︎ Checked to see if the issue has already been raised
☐ Created an executable example that demonstrates the issue using either:
• a Dockerfile
• a fork of https://github.com/pact-foundation/pact-ruby-standalone-e2e-example
• a Git repository with a Travis or Appveyor (or similar) build
• a gist with all the relevant code and full instructions on how to run it
N/A
Software versions
• pact-ruby-standalone: eg 2.4.1
Expected behaviour
Vulnerabilities fixed by updating the used rack version. Current version: 2.2.8 Versions with fix: 2.2.8.1, 3.0.9.1
Vulnerabilities fixed by updating the used openssl version. Current version 3.1.0 Versions with fix: 3.1.5, 3.2.1
Actual behaviour
High vulnerabilities raised in /home/builder/deps/pact/lib/vendor/ruby/3.2.0/specifications/rack-2.2.8.gemspec
Warn vulnerabilities raised in /home/builder/deps/pact/lib/ruby/lib/ruby/gems/3.2.0/specifications/default/openssl-3.1.0.gemspec
Steps to reproduce
Run software as normal. Vulnerabilities spotted through internal image scanning which includes the pact standalone binaries.
pact-foundation/pact-ruby-standaloneGitHub
02/27/2024, 2:24 PM