Skip to content

Conversation

@brandur
Copy link
Contributor

@brandur brandur commented Dec 20, 2024

The locked version of REXML has an open vulnerability according to
GitHub. Here, update that, and also do a full bundle update pass while
we're at it to get the other dependencies as well.

The locked version of REXML has an open vulnerability according to
GitHub. Here, update that, and also do a full `bundle update` pass while
we're at it to get the other dependencies as well.
@brandur
Copy link
Contributor Author

brandur commented Dec 20, 2024

NM. The latest ActiveRecord breaks on 3.1. Just going to make the smaller change of updating REXML only for now. Once 3.4 is released next week we can deprecate 3.1 in the CI matrix.

@brandur brandur closed this Dec 20, 2024
@brandur brandur deleted the brandur-update-dependencies branch December 20, 2024 05:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants