Skip to content

[pull] master from ruby:master#935

Merged
pull[bot] merged 4 commits intoturkdevops:masterfrom
ruby:master
Apr 15, 2026
Merged

[pull] master from ruby:master#935
pull[bot] merged 4 commits intoturkdevops:masterfrom
ruby:master

Conversation

@pull
Copy link
Copy Markdown

@pull pull bot commented Apr 15, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

matzbot and others added 4 commits April 15, 2026 07:13
…direct dependencies.

Print a warning when a confusion by the indirect dependencies may happen.
See CVE-2020-36327 for the security risk.

ruby/rubygems@403d6744b2
…havior

The original PR added @Remote and aggregate_global_source? checks to
precompute_source_requirements_for_indirect_dependencies?, but these
conditions did not exist in the current codebase and would change the
method's behavior in cases where @Remote is false or
aggregate_global_source? is true. Since the goal is only to warn when
falling back to the insecure aggregate resolution path, keep the
existing condition as-is and just add the warning on the false branch.

Simplify the corresponding tests accordingly.

ruby/rubygems@ddd292acf1

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
ruby/rubygems@97d05b3fc5

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@pull pull bot locked and limited conversation to collaborators Apr 15, 2026
@pull pull bot added the ⤵️ pull label Apr 15, 2026
@pull pull bot merged commit 75387fd into turkdevops:master Apr 15, 2026
0 of 2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants