From b5ea6784b259055f52de33a289eb8b1b711a73ce Mon Sep 17 00:00:00 2001 From: Alan Guo Xiang Tan Date: Wed, 13 Apr 2022 10:33:37 +0800 Subject: [PATCH] Bump base Ruby version to 2.7.6 Pulls in fix for CVE-2022-28739 https://www.ruby-lang.org/en/news/2022/04/12/buffer-overrun-in-string-to-float-cve-2022-28739/ --- image/base/install-ruby | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/image/base/install-ruby b/image/base/install-ruby index 0ad7cca..0c77c18 100755 --- a/image/base/install-ruby +++ b/image/base/install-ruby @@ -1,9 +1,9 @@ #!/bin/bash set -e -RUBY_VERSION="2.7.5" +RUBY_VERSION="2.7.6" -mkdir /src +mkdir /src git -C /src clone https://github.com/rbenv/ruby-build.git cd /src/ruby-build && ./install.sh cd / && rm -fr /src -- 2.25.1