Skip to content

build(deps): bump rack from 2.2.8.1 to 2.2.22 in /appengine/standard-static-files/rails#1651

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/bundler/appengine/standard-static-files/rails/rack-2.2.22
Open

build(deps): bump rack from 2.2.8.1 to 2.2.22 in /appengine/standard-static-files/rails#1651
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/bundler/appengine/standard-static-files/rails/rack-2.2.22

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 17, 2026

Bumps rack from 2.2.8.1 to 2.2.22.

Commits
  • 0cc2e00 Bump patch version.
  • a5725c0 Prevent directory traversal via root prefix bypass.
  • 175e7d2 XSS injection via malicious filename in Rack::Directory.
  • 3472037 Fix changelog.
  • 851dc02 Bump patch version.
  • 1e6aeda Allow Multipart head to span read boundary. (#2392)
  • 6ef5915 Bump patch version.
  • 4e2c903 Unbounded read in Rack::Request form parsing can lead to memory exhaustion.
  • fba2c8b Improper handling of proxy headers in Rack::Sendfile may allow proxy bypass.
  • ed3d834 Normalize adivsories links.
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [rack](https://github.com/rack/rack) from 2.2.8.1 to 2.2.22.
- [Release notes](https://github.com/rack/rack/releases)
- [Changelog](https://github.com/rack/rack/blob/main/CHANGELOG.md)
- [Commits](rack/rack@v2.2.8.1...v2.2.22)

---
updated-dependencies:
- dependency-name: rack
  dependency-version: 2.2.22
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Feb 17, 2026
@dependabot dependabot bot requested review from a team as code owners February 17, 2026 19:39
@dependabot dependabot bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Feb 17, 2026
@trusted-contributions-gcf trusted-contributions-gcf bot added the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Feb 17, 2026
@product-auto-label product-auto-label bot added the samples Issues that are directly related to samples. label Feb 17, 2026
@kokoro-team kokoro-team removed the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Feb 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant