[Snyk] Security upgrade rack from 1.6.4 to 2.2.23 - #16
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-RACK-15878254 - https://snyk.io/vuln/SNYK-RUBY-RACK-15878260 - https://snyk.io/vuln/SNYK-RUBY-RACK-15878256 - https://snyk.io/vuln/SNYK-RUBY-RACK-15878237 - https://snyk.io/vuln/SNYK-RUBY-RACK-15878255 - https://snyk.io/vuln/SNYK-RUBY-RACK-15878257 - https://snyk.io/vuln/SNYK-RUBY-RACK-15878258 - https://snyk.io/vuln/SNYK-RUBY-RACK-15878259 - https://snyk.io/vuln/SNYK-RUBY-RACK-15878035
|
This major version upgrade from Rack 1.x to 2.x introduces several significant breaking changes to the Rack specification and drops support for older Ruby versions. Key Breaking Changes:
Recommendation: Source: Rack CHANGELOG, Rack Upgrade Guide
|
|
🐕 Corgea found the following new SCA issues in the codebase:
Showing 3 out of 8 findings. See full results |
Snyk has created this PR to fix 9 vulnerabilities in the rubygems dependencies of this project.
Snyk changed the following file(s):
GemfileGemfile.lockVulnerabilities that will be fixed with an upgrade:
SNYK-RUBY-RACK-15878254
SNYK-RUBY-RACK-15878260
SNYK-RUBY-RACK-15878256
SNYK-RUBY-RACK-15878237
SNYK-RUBY-RACK-15878255
SNYK-RUBY-RACK-15878257
SNYK-RUBY-RACK-15878258
SNYK-RUBY-RACK-15878259
SNYK-RUBY-RACK-15878035
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Denial of Service (DoS)