From: "hsbt (Hiroshi SHIBATA) via ruby-core" Date: 2023-03-29T05:36:21+00:00 Subject: [ruby-core:113035] [Ruby master Bug#19556] Backport latest versions of URI Issue #19556 has been reported by hsbt (Hiroshi SHIBATA). ---------------------------------------- Bug #19556: Backport latest versions of URI https://bugs.ruby-lang.org/issues/19556 * Author: hsbt (Hiroshi SHIBATA) * Status: Closed * Priority: Normal * Backport: 2.7: DONE, 3.0: REQUIRED, 3.1: REQUIRED, 3.2: DONE ---------------------------------------- https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/ has been published. We should upgrade URI version each stable branch. * [for Ruby 3.0](https://github.com/ruby/ruby/pull/7607) * [for Ruby 3.1](https://github.com/ruby/ruby/pull/7605) -- https://bugs.ruby-lang.org/ ______________________________________________ ruby-core mailing list -- ruby-core@ml.ruby-lang.org To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org ruby-core info -- https://ml.ruby-lang.org/mailman3/postorius/lists/ruby-core.ml.ruby-lang.org/