Skip to content

[AUTOPATCHER-CORE] Upgrade rubygem-faraday to 2.14.1 for CVE-2026-25765#15858

Closed
CBL-Mariner-Bot wants to merge 1 commit into3.0-devfrom
cblmargh/rubygem-faraday-upgrade-to-2.14.1-3.0-dev
Closed

[AUTOPATCHER-CORE] Upgrade rubygem-faraday to 2.14.1 for CVE-2026-25765#15858
CBL-Mariner-Bot wants to merge 1 commit into3.0-devfrom
cblmargh/rubygem-faraday-upgrade-to-2.14.1-3.0-dev

Conversation

@CBL-Mariner-Bot
Copy link
Copy Markdown
Collaborator

@Kanishk-Bansal
Copy link
Copy Markdown
Contributor

/azurepipelines run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

Copy link
Copy Markdown
Contributor

@xordux xordux left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No breaking changes as per release notes
Build is passing
There are no P-tests

Github checks failed due to failed P-Test of systemd and libguestfs, which are not new failures.

@Kanishk-Bansal
Copy link
Copy Markdown
Contributor

Full Build

@Kanishk-Bansal Kanishk-Bansal added the ready-for-stable-review PR has passed initial review and is now ready for a second-level stable maintainer review label Mar 11, 2026
Copy link
Copy Markdown
Contributor

@kgodara912 kgodara912 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Major version upgrade but in the same API line. Though there are few corner cases where it can break the behavior in case the client was using internal behavior of faraday gem or other dependency of Faraday package. There is already a patch available which has only a minor hunk failure and easily back portable. Please use the patch, https://github.com/lostisland/faraday/commit/a6d3a3a0bf59c2ab307d0abd91bc126aef5561bc

@Kanishk-Bansal Kanishk-Bansal removed security ready-for-stable-review PR has passed initial review and is now ready for a second-level stable maintainer review CVE-fixed-by-upgrade CVE fixed by package upgrade labels Apr 7, 2026
@Kanishk-Bansal
Copy link
Copy Markdown
Contributor

closing in favour #16430

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants