From 2880102b1b25229ef6120d472c3c7f6b523618fa Mon Sep 17 00:00:00 2001 From: xavier Date: Thu, 19 Sep 2024 15:07:37 +0200 Subject: [PATCH] Bump ruby-saml from v1.7 to v1.17 A security vulnerabilty affecting the ruby-saml library was discovered * CVE-2024-4540 * https://www.cve.org/CVERecord?id=CVE-2024-4540 This vulnerability was fixed in ruby-saml v1.17.0 * changelog: https://github.com/SAML-Toolkits/ruby-saml/releases/tag/v1.17.0 --- devise_saml_authenticatable.gemspec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/devise_saml_authenticatable.gemspec b/devise_saml_authenticatable.gemspec index e8f3a82..c672ffb 100644 --- a/devise_saml_authenticatable.gemspec +++ b/devise_saml_authenticatable.gemspec @@ -19,5 +19,5 @@ Gem::Specification.new do |gem| gem.required_ruby_version = ">= 2.6.0" gem.add_dependency("devise","> 2.0.0") - gem.add_dependency("ruby-saml","~> 1.7") + gem.add_dependency("ruby-saml","~> 1.17") end