Skip to content

[AUTOPATCHER-CORE] Upgrade rubygem-concurrent-ruby to 1.3.7 for CVE-2026-54904, CVE-2026-54905, CVE-2026-54906#17836

Merged
jslobodzian merged 1 commit into
fasttrack/3.0from
cblmargh/rubygem-concurrent-ruby-upgrade-to-1.3.7-fasttrack/3.0
Jun 30, 2026
Merged

[AUTOPATCHER-CORE] Upgrade rubygem-concurrent-ruby to 1.3.7 for CVE-2026-54904, CVE-2026-54905, CVE-2026-54906#17836
jslobodzian merged 1 commit into
fasttrack/3.0from
cblmargh/rubygem-concurrent-ruby-upgrade-to-1.3.7-fasttrack/3.0

Conversation

@CBL-Mariner-Bot

Copy link
Copy Markdown
Collaborator

[AUTOPATCHER-CORE] Upgrade rubygem-concurrent-ruby to 1.3.7 for CVE-2026-54904, CVE-2026-54905, CVE-2026-54906
Upgrade pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1148422&view=results

@Kanishk-Bansal Kanishk-Bansal left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, minor version bump to fix the CVE.
the package builds fine, new tarball uploaded.
very less changes which are mostly maintenance - ruby-concurrency/concurrent-ruby@v1.2.2...v1.3.7

  • Buddy Build
  • Tarballs uploaded
  • Changelog entry
  • CG Manifest
  • PR has security & CVE-fixed-by-upgrade tag

@Kanishk-Bansal Kanishk-Bansal added the CVEFixReadyForMaintainerReview When a CVE fix has been reviewed by release manager and is ready for stable maintainer review label Jun 28, 2026
@jslobodzian jslobodzian merged commit da80673 into fasttrack/3.0 Jun 30, 2026
30 checks passed
@jslobodzian jslobodzian deleted the cblmargh/rubygem-concurrent-ruby-upgrade-to-1.3.7-fasttrack/3.0 branch June 30, 2026 01:55
@CBL-Mariner-Bot

Copy link
Copy Markdown
Collaborator Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Automatic PR AutoUpgrade Core CVEFixReadyForMaintainerReview When a CVE fix has been reviewed by release manager and is ready for stable maintainer review fasttrack/3.0 PRs Destined for Azure Linux 3.0 Packaging

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants