-
Notifications
You must be signed in to change notification settings - Fork 307
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ruby3.2-faraday/2.10.1 package update #25340
Conversation
octo-sts
bot
commented
Jul 31, 2024
Signed-off-by: wolfi-bot <[email protected]>
Package ruby3.2-faraday: Click to expand/collapsePackage ruby3.2-faraday:
Added: /usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/CHANGELOG.md bincapz found differences: Click to expand/collapseChanged: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/examples/client_spec.rb [✅ → ✅ LOW]1 new behaviors
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/adapter_registry_spec.rb [✅ LOW → ✅ ]2 removed behaviors
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/adapter/test.rb [✅ →
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | with_user_agent |
+MEDIUM | ref/words/exclamation | gets very excited | !! |
+LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
+LOW | net/http/request | makes HTTP requests | User-Agent |
+LOW | ref/site/url | contains embedded HTTPS URLs | lostisland/faraday#1444 |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/options/ssl_options.rb [✅ → ⚠️ MEDIUM]
3 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | builtin/openssl | This binary includes OpenSSL source code | OpenSSL/ |
+LOW | ref/site/url | contains embedded HTTPS URLs | ruby/openssl#60 https://ruby-doc.org/stdlib-2.5.1/libdoc/openssl/rdoc/OpenSSL/SSL.html https://ruby-doc.org/stdlib-2.5.1/libdoc/openssl/rdoc/OpenSSL/SSL/SSLCont |
+LOW | secrets/private_key | References private keys | private_key |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/spec/faraday/utils/headers_spec.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/rack_builder_spec.rb (similarity: 0.93) [✅ LOW → ✅ ]
2 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | net/http/request | makes HTTP requests | HTTP/1. |
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/ |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/utils.rb [✅ LOW → ✅ ]
2 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | net/http/request | makes HTTP requests | HTTP/1. |
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/ |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/utils/params_hash.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/options/proxy_options.rb [✅ → ✅ LOW]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/words/password | references a 'password' | password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/var/lib/db/sbom/ruby3.2-faraday-2.10.1-r0.spdx.json
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
4 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | user_agent |
-LOW | net/http/request | makes HTTP requests | User-Agent |
-LOW | net/http_proxy | discover proxy address via environment | HTTP_PROXY |
-LOW | ref/words/password | references a 'password' | password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/options/env_spec.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/utils_spec.rb [✅ → ⚠️ MEDIUM]
4 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | user_agent |
+LOW | net/http/request | makes HTTP requests | HTTP/1. |
+LOW | ref/site/url | contains embedded HTTP URLs | http://example.com/abc |
+LOW | secrets/private_key | References private keys | private_key |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/options/env.rb [✅ → ⚠️ MEDIUM]
2 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/exclamation | gets very excited | !! |
+LOW | ref/words/password | references a 'password' | - Proxy server password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday_spec.rb [⚠️ MEDIUM → ✅ ]
6 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | user_agent |
-LOW | compression/gzip | works with gzip files | gzip |
-LOW | net/http/accept/encoding | set HTTP response encoding format (example: gzip) | Accept-Encoding |
-LOW | net/http/request | makes HTTP requests | User-Agent |
-LOW | net/socket/send | send a message to a socket | send socket |
-LOW | ref/site/url | contains embedded HTTPS URLs | lostisland/faraday#718 |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/spec_helper.rb [✅ → ⚠️ MEDIUM]
3 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./lib ./spec |
+LOW | random/insecure | generate random numbers insecurely | srand |
+LOW | ref/site/url | contains embedded HTTP URLs | http://rspec.info/blog/2012/06/rspecs-new-expectation-syntax/ http://rspec.info/blog/2014/05/notable-changes-in-rspec-3/ http://rubydoc.info/gems/rspec-core/RSpec/Core/Configuration http://www.teaisaweso.me/blog/2013/05/27/rspecs-new-message-expectation- |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/spec/faraday/request_spec.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/middleware_registry_spec.rb (similarity: 0.91) [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/request_spec.rb [✅ → ✅ LOW]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/response/json_spec.rb [✅ → ✅ LOW]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/version.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/logging/formatter.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/utils/headers_spec.rb [✅ → ✅ LOW]
2 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | net/http/request | makes HTTP requests | HTTP/1. |
+LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/ |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/request/instrumentation_spec.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/adapter_registry.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/spec/faraday/request_spec.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/options/options_spec.rb (similarity: 0.91) [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/response/raise_error.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/support/disabling_stub.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/support/shared_examples/adapter.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/spec/faraday/utils/headers_spec.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/params_encoders/flat_spec.rb (similarity: 0.90) [✅ LOW → ✅ ]
2 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | net/http/request | makes HTTP requests | HTTP/1. |
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/ |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/spec/faraday/connection_spec.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/connection_spec.rb (similarity: 0.99)
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/middleware_spec.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/support/streaming_response_checker.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/middleware_registry.rb [⚠️ MEDIUM → ✅ ]
5 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | user_agent |
-LOW | net/http/request | makes HTTP requests | User-Agent |
-LOW | net/http_proxy | discover proxy address via environment | HTTP_PROXY |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://ahttpbingo.org/sake.html https://google.co.uk https://httpbingo.org/foo https://httpbingo.org/get/sake.html https://proxy.com |
-LOW | ref/words/password | references a 'password' | password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/request/url_encoded.rb [✅ → ⚠️ MEDIUM]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/url/encode | encodes URL, likely to pass GET variables | urlencode |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/encoders/flat_params_encoder.rb [⚠️ MEDIUM → ✅ ]
5 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | user_agent |
-LOW | net/http/request | makes HTTP requests | User-Agent |
-LOW | net/http_proxy | discover proxy address via environment | HTTP_PROXY |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://ahttpbingo.org/sake.html https://google.co.uk https://httpbingo.org/foo https://httpbingo.org/get/sake.html https://proxy.com |
-LOW | ref/words/password | references a 'password' | password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/request/json_spec.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/adapter.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/words/password | references a 'password' | password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/options/request_options.rb [⚠️ MEDIUM → ✅ ]
6 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | user_agent |
-LOW | compression/gzip | works with gzip files | gzip |
-LOW | net/http/accept/encoding | set HTTP response encoding format (example: gzip) | Accept-Encoding |
-LOW | net/http/request | makes HTTP requests | User-Agent |
-LOW | net/socket/send | send a message to a socket | send socket |
-LOW | ref/site/url | contains embedded HTTPS URLs | lostisland/faraday#718 |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/response/logger_spec.rb [✅ → ✅ LOW]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/words/password | references a 'password' | password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/support/shared_examples/params_encoder.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/request/url_encoded_spec.rb [✅ → ⚠️ MEDIUM]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/url/encode | encodes URL, likely to pass GET variables | urlencode |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/spec/faraday/rack_builder_spec.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/adapter/test_spec.rb (similarity: 0.92) [✅ → ⚠️ MEDIUM]
4 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | with_user_agent |
+LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
+LOW | net/http/request | makes HTTP requests | User-Agent |
+LOW | ref/site/url | contains embedded HTTP URLs | http://domain.test/bait http://domain.test/hello http://foo.com/foo?a=1 http://wrong.test/bait http://wrong.test/hello |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/request/instrumentation.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/adapter_spec.rb [⚠️ MEDIUM → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/url/encode | encodes URL, likely to pass GET variables | urlencode |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/options.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/response/raise_error_spec.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/response/json.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/external_adapters/faraday_specs_setup.rb [✅ LOW → ✅ ]
2 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | https://lostisland.github.io/faraday/usage/. |
-LOW | ref/words/password | references a 'password' | - Proxy server password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/middleware.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/params_encoders/nested_spec.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/options/request_options_spec.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/request/json.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/words/password | references a 'password' | password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/methods.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/words/password | references a 'password' | password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/request/authorization_spec.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/request/authorization.rb [✅ → ✅ LOW]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/words/password | references a 'password' | be a login and password pair |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/examples/client_test.rb [✅ → ✅ LOW]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/spec/faraday/response/logger_spec.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/response_spec.rb (similarity: 0.95)
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://lostisland.github.io/faraday |
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/words/password | references a 'password' | password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/response.rb [✅ LOW → ⚠️ MEDIUM]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/exclamation | gets very excited | !! |
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/words/password | references a 'password' | password |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/lib/faraday/error.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday.rb (similarity: 0.95) [✅ → ✅ LOW]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://faraday.com |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/support/helper_methods.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/words/password | references a 'password' | password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/support/fake_safe_buffer.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/spec/faraday/request_spec.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/error_spec.rb (similarity: 0.95) [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/options/connection_options.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/response/logger.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/error.rb [✅ LOW → ✅ ]
2 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | net/http/request | makes HTTP requests | HTTP/1. |
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/ |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/lib/faraday/methods.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/rack_builder.rb (similarity: 0.92) [✅ → ✅ LOW]
2 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://lostisland.github.io/faraday/usage/. |
+LOW | ref/words/password | references a 'password' | - Proxy server password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/request.rb [✅ → ✅ LOW]
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTP URLs | http://localhost?a=1 |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/utils/headers.rb [✅ → ⚠️ MEDIUM]
2 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | user_agent |
+LOW | net/http/request | makes HTTP requests | User-Agent |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/parameters.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/support/shared_examples/request_method.rb [✅ → ⚠️ MEDIUM]
6 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | user_agent |
+LOW | compression/gzip | works with gzip files | gzip |
+LOW | net/http/accept/encoding | set HTTP response encoding format (example: gzip) | Accept-Encoding |
+LOW | net/http/request | makes HTTP requests | User-Agent |
+LOW | net/socket/send | send a message to a socket | send socket |
+LOW | ref/site/url | contains embedded HTTPS URLs | lostisland/faraday#718 |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/faraday/options/proxy_options_spec.rb [✅ → ✅ LOW]
2 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTP URLs | http://example.org |
+LOW | ref/words/password | references a 'password' | password |
Moved: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.0/lib/faraday/methods.rb -> /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/connection.rb (similarity: 0.94) [✅ → ⚠️ MEDIUM]
5 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/http/post | submit content to websites | HTTP POST http |
+MEDIUM | ref/words/agent | references an 'agent' | user_agent |
+MEDIUM | ref/words/exclamation | gets very excited | !! |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://api.github.com/gists/GIST_ID/star https://httpbingo.org/api/nigiri?token=abc https://httpbingo.org/api?token=abc |
+LOW | ref/words/password | references a 'password' | any password from URI username and password yieldparam password |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/lib/faraday/encoders/nested_params_encoder.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Changed: /tmp/wolfictl-apk-2036094694/ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.10.1/spec/support/faraday_middleware_subclasses.rb [✅ LOW → ✅ ]
1 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |