Skip to content

[AUTOPATCHER-CORE] Upgrade rubygem-concurrent-ruby to 1.3.7 for CVE-2026-54904, CVE-2026-54905, CVE-2026-54906#17836

Open
CBL-Mariner-Bot wants to merge 1 commit into
fasttrack/3.0from
cblmargh/rubygem-concurrent-ruby-upgrade-to-1.3.7-fasttrack/3.0
Open

[AUTOPATCHER-CORE] Upgrade rubygem-concurrent-ruby to 1.3.7 for CVE-2026-54904, CVE-2026-54905, CVE-2026-54906#17836
CBL-Mariner-Bot wants to merge 1 commit into
fasttrack/3.0from
cblmargh/rubygem-concurrent-ruby-upgrade-to-1.3.7-fasttrack/3.0

Conversation

@CBL-Mariner-Bot

Copy link
Copy Markdown
Collaborator

[AUTOPATCHER-CORE] Upgrade rubygem-concurrent-ruby to 1.3.7 for CVE-2026-54904, CVE-2026-54905, CVE-2026-54906
Upgrade pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1148422&view=results

@Kanishk-Bansal Kanishk-Bansal left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, minor version bump to fix the CVE.
the package builds fine, new tarball uploaded.
very less changes which are mostly maintenance - ruby-concurrency/concurrent-ruby@v1.2.2...v1.3.7

  • Buddy Build
  • Tarballs uploaded
  • Changelog entry
  • CG Manifest
  • PR has security & CVE-fixed-by-upgrade tag

@Kanishk-Bansal Kanishk-Bansal added the CVEFixReadyForMaintainerReview When a CVE fix has been reviewed by release manager and is ready for stable maintainer review label Jun 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Automatic PR AutoUpgrade Core CVEFixReadyForMaintainerReview When a CVE fix has been reviewed by release manager and is ready for stable maintainer review fasttrack/3.0 PRs Destined for Azure Linux 3.0 Packaging

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants