Skip to content

Bump puma from 5.6.2 to 5.6.4

libautomation requested to merge dependabot/bundler/puma-5.6.4 into main

Bumps puma from 5.6.2 to 5.6.4.

Release notes

Sourced from puma's releases.

5.6.4

  • Security
    • Close several HTTP Request Smuggling exploits (CVE-2022-24790)

The 5.6.3 release was a mistake (released the wrong branch), 5.6.4 is correct.

Changelog

Sourced from puma's changelog.

5.6.4 / 2022-03-30

  • Security
    • Close several HTTP Request Smuggling exploits (CVE-2022-24790)
Commits

Merge request reports