Skip to content

fix: bump addressable + concurrent-ruby (3 CVEs) - #25

Merged
minerva-sky merged 4 commits into
mainfrom
fix/addressable-cve
Sep 4, 2026
Merged

fix: bump addressable + concurrent-ruby (3 CVEs)#25
minerva-sky merged 4 commits into
mainfrom
fix/addressable-cve

Conversation

@minerva-sky

Copy link
Copy Markdown
Collaborator

The Advisories job that landed with #7 flags addressable 2.8.7 (CVE-2026-35611 / GHSA-h27x-rffw-24p4). Conservative bump to 2.9.0 clears it. Lockfile-only.

🤖 Generated with Claude Code

@minerva-sky minerva-sky changed the title fix: bump addressable to 2.9.0 (CVE-2026-35611) fix: bump addressable + concurrent-ruby (3 CVEs) Sep 2, 2026
@minerva-sky
minerva-sky merged commit 04b3ec4 into main Sep 4, 2026
2 checks passed
@minerva-sky
minerva-sky deleted the fix/addressable-cve branch September 4, 2026 13:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant