Skip to content

Bump httparty version and update author#222

Merged
asatwal merged 1 commit intomainfrom
bump-httparty-version
Jan 7, 2026
Merged

Bump httparty version and update author#222
asatwal merged 1 commit intomainfrom
bump-httparty-version

Conversation

@asatwal
Copy link
Collaborator

@asatwal asatwal commented Jan 7, 2026

Context

HttParty Has Potential SSRF Vulnerability That Leads to API Key Leakage
Advisory here:
GHSA-hm5p-x4rq-38w4

The usage by dfe-analytics does not put it at risk from that CVE.

Changes proposed in this pull request:

Bunp version of httparty to the latest

@asatwal asatwal self-assigned this Jan 7, 2026
@asatwal asatwal force-pushed the bump-httparty-version branch from 5463353 to e813e99 Compare January 7, 2026 10:32
@asatwal asatwal merged commit 0370043 into main Jan 7, 2026
9 of 10 checks passed
@asatwal asatwal deleted the bump-httparty-version branch January 7, 2026 11:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants