Skip to content

Vulnerability in Rouge 2.0.7 #21192

@dvelopmberg

Description

@dvelopmberg

New Issue Checklist

Issue Description

The fastlane release 2.212.1 is conusming xcpretty 0.3.0
https://github.com/fastlane/fastlane/blob/master/Gemfile.lock

xcpretty 0.3.0 is conusming rouge 2.0.7 and this version has vulnerabilities
https://ossindex.sonatype.org/vulnerability/sonatype-2021-4771?component-type=gem&component-name=rouge&utm_source=dependency-track&utm_medium=integration&utm_content=v4.5.0

I don't know what to do, because the xcpretty project is dead i think? There are no changes since 2018
and the active pull request with the update of rouge is open since end of 2022
xcpretty/xcpretty#383

Command executed

Not relevant.

Complete output when running fastlane, including the stack trace and command used
 Not relevant 

Environment

 Not relevant 

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions