mirror of
https://github.com/basecamp/once-campfire.git
synced 2026-09-10 02:32:02 +09:00
Update mail to 2.9.1 for GHSA-mvxr-6m87-mv2q (#248)
The advisory (email address spoofing via malformed RFC 2047 encoded-words, CVE-2026-63435) landed in ruby-advisory-db on 2026-08-18, turning the gem audit red since the audit pulls a live advisory DB. 2.9.1 is the patch release for exactly this CVE.
This commit is contained in:
+1
-1
@@ -204,7 +204,7 @@ GEM
|
||||
loofah (2.25.2)
|
||||
crass (~> 1.0.2)
|
||||
nokogiri (>= 1.12.0)
|
||||
mail (2.9.0)
|
||||
mail (2.9.1)
|
||||
logger
|
||||
mini_mime (>= 0.1.1)
|
||||
net-imap
|
||||
|
||||
Reference in New Issue
Block a user