Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No update to CHANGES.md for v2.3.0 #397

Closed
baburdick opened this issue Dec 28, 2019 · 5 comments
Closed

No update to CHANGES.md for v2.3.0 #397

baburdick opened this issue Dec 28, 2019 · 5 comments

Comments

@baburdick
Copy link

Why no descriptive record of this large set of changes?

@disambiguator
Copy link

+1 to this. Given that this is the recommended fix to https://www.ruby-lang.org/en/news/2020/03/19/json-dos-cve-2020-10663/, a changelog would help devs feel confident in updating this dependency. Thank you!

@stmllr
Copy link

stmllr commented Mar 24, 2020

Can anyone please point to the commit which fixed the issue?

@chulkilee
Copy link

Diff is v2.2.0...v2.3.0 but not sure which commit actually fixed it. 🤷

@baburdick
Copy link
Author

Exactly.

marcandre added a commit to marcandre/json that referenced this issue Jun 30, 2020
marcandre added a commit to marcandre/json that referenced this issue Jun 30, 2020
@marcandre
Copy link
Member

I've opened #424 with the list of changes (all bug fixes).

Diff is v2.2.0...v2.3.0 but not sure which commit actually fixed it. 🤷

Indeed! I believe the fix is hiding in this PR which was copied over to json in this commit

@hsbt hsbt closed this as completed in 1a6f004 Jun 30, 2020
hsbt added a commit that referenced this issue Jun 30, 2020
Update Changes for 2.3.0 [Fixes #397]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants