Skip to content

dep: bump puma from 5.6.2 to 5.6.4

George Koltsov requested to merge dependabot-bundler-puma-5.6.4 into master

Bumps puma from 5.6.2 to 5.6.4.

Release notes

Sourced from puma's releases.

5.6.4

  • Security
    • Close several HTTP Request Smuggling exploits (CVE-2022-24790)

The 5.6.3 release was a mistake (released the wrong branch), 5.6.4 is correct.

Changelog

Sourced from puma's changelog.

5.6.4 / 2022-03-30

  • Security
    • Close several HTTP Request Smuggling exploits (CVE-2022-24790)
Commits


Dependabot commands
You can trigger Dependabot actions by commenting on this MR
  • @dependabot-bot rebase will rebase this MR
  • @dependabot-bot recreate will recreate this MR rewriting all the manual changes and resolving conflicts

Merge request reports