Skip to content

Bump fastlane to fix rubyzip vulnerability - #775

Merged
iangmaia merged 2 commits into
trunkfrom
iangmaia/fix-dependabot-69-rubyzip
Sep 28, 2026
Merged

iangmaia merged 2 commits into
trunkfrom
iangmaia/fix-dependabot-69-rubyzip

Conversation

@iangmaia

@iangmaia iangmaia commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bump Fastlane to ~> 2.240 to require patched rubyzip versions, resolving Dependabot alert #69 (CVE-2026-85396).

@iangmaia iangmaia self-assigned this Sep 28, 2026
@iangmaia iangmaia added the dependencies Pull requests that update a dependency file label Sep 28, 2026
@iangmaia
iangmaia force-pushed the iangmaia/fix-dependabot-69-rubyzip branch from 69b4d78 to eb5068a Compare September 28, 2026 16:21
@iangmaia
iangmaia requested a balanced review from Copilot September 28, 2026 16:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The dependency constraints, resolved lockfile, and changelog consistently implement the security update.

Review effort: Balanced
Findings: None

What changed in this PR

Updates Fastlane and Faraday to secure versions that resolve the rubyzip vulnerability.

Changes:

  • Requires Fastlane ~> 2.240.
  • Updates Faraday to secure 2.14.x releases.
  • Regenerates dependencies with rubyzip 3.7.0.
File Description
Gemfile.lock Locks updated secure dependencies.
Gemfile Updates the Faraday constraint.
fastlane-plugin-wpmreleasetoolkit.gemspec Raises the Fastlane requirement.
CHANGELOG.md Records the vulnerability fix.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@iangmaia
iangmaia marked this pull request as ready for review September 28, 2026 16:36
@iangmaia
iangmaia requested a review from a team as a code owner September 28, 2026 16:36
Comment thread Gemfile Outdated
Comment on lines +12 to +13
# Security: https://github.com/advisories/GHSA-98m9-hrrm-r99r
gem 'faraday', '~> 2.14', '>= 2.14.3'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure it's strictly worth it adding the comment and forcing >= 2.14.3 in the Gemfile given that the version that was resolved in Gemfile.lock is already 2.14.4 so it won't go backwards after that… 🤷

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed -- updated on 85faf49

@iangmaia
iangmaia merged commit 9faa00d into trunk Sep 28, 2026
6 checks passed
@iangmaia
iangmaia deleted the iangmaia/fix-dependabot-69-rubyzip branch September 28, 2026 18:14
Copilot AI mentioned this pull request Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants