Skip to content

Use Psych 5.1#7626

Merged
headius merged 2 commits intojruby:masterfrom
headius:psych_5.1_jruby_9.4
Feb 7, 2023
Merged

Use Psych 5.1#7626
headius merged 2 commits intojruby:masterfrom
headius:psych_5.1_jruby_9.4

Conversation

@headius
Copy link
Member

@headius headius commented Feb 6, 2023

Fixes #7570

Fixes #6365

See #7600 for the same PR against 9.3, which needs work because the tests do not pass with newer Psych's safe_load logic.

@headius headius added this to the JRuby 9.4.1.0 milestone Feb 6, 2023
Fixes jruby#7570

Fixes jruby#6365

See jruby#7600 for the same PR against 9.3, which needs work because
the tests do not pass with newer Psych's safe_load logic.
@headius headius force-pushed the psych_5.1_jruby_9.4 branch from 88e3340 to 47105c5 Compare February 7, 2023 12:27
@headius headius merged commit 5198407 into jruby:master Feb 7, 2023
@headius headius deleted the psych_5.1_jruby_9.4 branch February 7, 2023 14:31
headius added a commit to headius/asciidoctorj that referenced this pull request Sep 11, 2023
JRuby 9.4.3.0 includes an udpated Psych YAML library, which uses
SnakeYAML-Engine and avoids several CVEs against the original
SnakeYAML. By updating here, downstream users of asciidoctorj will
not run into security audit issues.

See related issues and PRs:

* jruby/jruby#7570
* jruby/jruby#7600
* jruby/jruby#7626
* jruby/jruby#7935
robertpanzer pushed a commit to robertpanzer/asciidoctorj that referenced this pull request Sep 17, 2023
JRuby 9.4.3.0 includes an udpated Psych YAML library, which uses
SnakeYAML-Engine and avoids several CVEs against the original
SnakeYAML. By updating here, downstream users of asciidoctorj will
not run into security audit issues.

See related issues and PRs:

* jruby/jruby#7570
* jruby/jruby#7600
* jruby/jruby#7626
* jruby/jruby#7935
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

New snakeyaml vulnerability has dropped, affects jruby-complete Psych syntax error changed in JRuby 9.2.13.0

1 participant