Skip to content

ISG-92 - Address security vulnerabilities#24

Merged
orweller merged 1 commit intomasterfrom
ISG-92/address-security-vulnerabilities
Mar 27, 2026
Merged

ISG-92 - Address security vulnerabilities#24
orweller merged 1 commit intomasterfrom
ISG-92/address-security-vulnerabilities

Conversation

@orweller
Copy link
Copy Markdown
Contributor

Summary

[4.6.0]

Changed

  1. Relax patch-level dependency pins to minor-level to allow security patch updates. (ISG-92)
  2. Remove transitive dependencies (logger, ostruct, rexml, thor) from gemspec; add rexml and thor as Gemfile security floor constraints. (ISG-92)

Checklist

  • Did we think two weeks into the future and not two years? Is this addition malleable to be changed tomorrow without being over-engineered today?
  • Have you updated the changelog with this behavior?

@orweller orweller self-assigned this Mar 26, 2026
@orweller orweller requested a review from a team as a code owner March 26, 2026 16:21
@orweller orweller added the dependencies Pull requests that update a dependency file label Mar 26, 2026
@orweller orweller merged commit 591515c into master Mar 27, 2026
7 checks passed
@orweller orweller deleted the ISG-92/address-security-vulnerabilities branch March 27, 2026 11:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Development

Successfully merging this pull request may close these issues.

2 participants