Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump ruby-saml version #127

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open

Conversation

stavros-wb
Copy link

No description provided.

@adamstegman
Copy link
Collaborator

Thank you for the contribution! Is there a specific issue in 1.7 or 1.8 such that they should no longer be allowed?

@stavros-wb
Copy link
Author

No vulnerabilities are fixed since 1.7 AFAIK. it's just bugfixes. Maybe @pitbulk knows something more, though

@pitbulk
Copy link

pitbulk commented Sep 5, 2018

Yes, not security improvement at all.

@adamstegman
Copy link
Collaborator

In that case, I don't think we need to require a higher version. Application users can upgrade to a higher version without any issues by running bundle update ruby-saml.

@hauserkristen
Copy link

Given this security incident, can we upgrade the ruby-saml version?

@adamstegman
Copy link
Collaborator

@hauserkristen There's nothing blocking application owners from updating, but yes it would be beneficial to update the minimum version of the dependency to help out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants