[DRE-maint] rubygems update

Antonio Terceiro terceiro at debian.org
Tue Mar 25 14:25:19 GMT 2025


Hi,

On Mon, Mar 24, 2025 at 03:25:15PM +0800, Sean Whitton wrote:
> Hello Antonio,
> 
> I'm looking at fixing CVE-2025-27221 as part of the Debian's LTS effort.
> 
> rubygems in sid has a vendored copy of the uri gem.  Updating the
> version of rubygems in sid should resolve the CVE-2025-27221 for
> rubygems in sid.
> 
> Do you think you'll be able to update rubygems in sid soon?  Or can I
> perhaps help?

Thanks for the prod. I will handle it.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-ruby-extras-maintainers/attachments/20250325/7eb23129/attachment.sig>


More information about the Pkg-ruby-extras-maintainers mailing list