Skip to content

Conversation

@flavorjones
Copy link
Member

What problem is this PR intended to solve?

Update vendored zlib to 1.3.1.

See #3172

Please note that Nokogiri is not vulnerable to the CVE patched in this version of zlib (which is related to the minizip library, which is not used by Nokogiri or its vendored libraries).

@flavorjones flavorjones added vendored/zlib backport Backport of a PR to the current release branch labels Apr 10, 2024
@flavorjones flavorjones reopened this Apr 10, 2024
@flavorjones flavorjones changed the base branch from main to v1.16.x April 10, 2024 16:07
@flavorjones flavorjones reopened this Apr 10, 2024
@flavorjones flavorjones force-pushed the flavorjones-dep-zlib-1.3.1_v1.16.x branch from 699b667 to edeac07 Compare April 10, 2024 16:08
@flavorjones flavorjones merged commit 1c329e9 into v1.16.x Apr 10, 2024
@flavorjones flavorjones deleted the flavorjones-dep-zlib-1.3.1_v1.16.x branch April 10, 2024 17:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport Backport of a PR to the current release branch vendored/zlib

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants