Skip to content

Fix rubyzip path traversal by updating Fastlane - #14

Merged
andre487 merged 1 commit into
mainfrom
fix/rubyzip-security
Sep 26, 2026
Merged

andre487 merged 1 commit into
mainfrom
fix/rubyzip-security

Conversation

@andre487

Copy link
Copy Markdown
Owner

Fixes the rubyzip path traversal vulnerability reported in Dependabot alert #1 (CVE-2026-85396 / GHSA-47m2-wp7j-p9vc).

Updates Fastlane from 2.238.0 to 2.240.1 and rubyzip from 2.4.1 to 3.7.0. The old Fastlane requirement excluded rubyzip 3.x; the new version requires rubyzip >= 3.4.0, the first patched version. The conservative Bundler update also adds cgi and updates security as required by Fastlane.

Validation:

  • bundle check passed.
  • bundle exec ruby scripts/test-play-release.rb passed.
  • bundle exec fastlane android play_release dry_run:true passed without uploading to Google Play.
  • A local ZIP extraction reproduction confirmed normal extraction succeeds and ../upload_backup/owned.sh cannot escape into a sibling directory.
  • git diff --check passed.

@andre487
andre487 enabled auto-merge (squash) September 26, 2026 16:41
@andre487
andre487 merged commit 42f03d5 into main Sep 26, 2026
3 checks passed
@andre487
andre487 deleted the fix/rubyzip-security branch September 26, 2026 16:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant