Skip to content

Bump jekyll-seo-tag, jekyll-feed, jekyll-redirect-from, and jekyll-remote-theme for security fixes - #965

Open
benbalter wants to merge 2 commits into
github:masterfrom
benbalter:security-bumps
Open

benbalter wants to merge 2 commits into
github:masterfrom
benbalter:security-bumps

Conversation

@benbalter

@benbalter benbalter commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

This bumps four plugins to releases that fix published security advisories. GitHub Pages currently pins affected versions of all four.

Gem Current New Advisory
jekyll-redirect-from 0.16.0 0.17.0 GHSA-xfg6-hjrc-hpvx: unescaped redirect_to allows script injection in generated redirect pages
jekyll-seo-tag 2.8.0 2.9.1 GHSA-572m-7cg5-6j5r: unescaped metadata fields and the JSON-LD block allow HTML/script injection
jekyll-feed 0.17.0 0.18.0 GHSA-3gx8-pqcm-38hw: post.lang isn't escaped in feed entries, plus a CDATA ]]> breakout
jekyll-remote-theme 0.4.3 0.6.2 Unblocks rubyzip >= 3.4.0 for CVE-2026-85396 (#966); 0.6.2 also avoids GHSA-3343-386p-v26g

Fixes #966.

Why jekyll-remote-theme 0.6.2 and not 0.5.2

0.4.3 requires rubyzip < 3.0, so sites using the github-pages gem can't pick up the rubyzip path traversal fix. 0.5.2 is the first release to allow rubyzip 3.x. But 0.5.0–0.6.0 are affected by GHSA-3343-386p-v26g: a local-path remote_theme can read files outside the site source, even in safe mode. That was fixed in 0.6.1, and 0.6.2 only changes metadata. 0.6.0 also caps download and zip extraction size and adds request timeouts.

With this branch, rubyzip resolves to 3.7.0, and bundle-audit reports no known vulnerabilities in the resolved bundle.

Notes for reviewers

  • jekyll-remote-theme 0.6.x requires Ruby >= 3.0 and adds a runtime dependency on the openssl gem (>= 3.1.2). The gemspec still says >= 2.3.0, but the CI matrix already starts at 3.0.
  • jekyll-remote-theme 0.5.0 added @latest refs, local filesystem paths (rejected in safe mode as of 0.6.1), and proxy support.
  • jekyll-seo-tag 2.9.x also includes the 2.9.0 features (for example twitter:description, 100-word description truncation, and canonical: false), so some sites' <head> output will change slightly.
  • jekyll-redirect-from 0.17.0 skips redirect_to targets that aren't http(s) or relative (with a build warning), and percent-encodes quotes, <, >, \ and similar characters in targets.

Testing

script/cibuild in Docker on Ruby 3.3: 157 of 158 specs pass. The one failure also happens on master: the unpinned jekyll-octicons dev dependency now adds data-component="Octicon" to its <svg> output, which breaks the <svg height="32" match in spec/github-pages/integration_spec.rb. The Ruby 3.0 Docker image doesn't build right now (its apt-get step fails), which is also unrelated to this change.

🤖 Generated with Claude Code

…y fixes

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@parkr

parkr commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Thanks for bumping, @benbalter.

@parkr

parkr commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

@benbalter #966 outlines that jekyll-remote-theme needs an update for security reasons as well. Would it make sense to fold that into this PR?

jekyll-remote-theme 0.4.3 caps rubyzip below 3.0, so github-pages users
can't pick up the fix for CVE-2026-85396, which only landed in rubyzip
3.4.0 (github#966). 0.5.2 was the first release to allow rubyzip 3.x, but
0.5.0 through 0.6.0 are affected by GHSA-3343-386p-v26g (local-path
remote_theme reads outside the site source in safe mode), so go straight
to 0.6.2. 0.6.0 also caps download and extraction size and adds request
timeouts.

0.6.x requires Ruby >= 3.0, which matches the oldest Ruby in the CI
matrix.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@benbalter benbalter changed the title Bump jekyll-seo-tag, jekyll-feed, and jekyll-redirect-from for security fixes Bump jekyll-seo-tag, jekyll-feed, jekyll-redirect-from, and jekyll-remote-theme for security fixes Sep 30, 2026
@benbalter

Copy link
Copy Markdown
Contributor Author

@parkr Good call, folded in via 09226aa. jekyll-remote-theme goes to 0.6.2 rather than 0.5.2 (the first release to allow rubyzip 3.x), because 0.5.0–0.6.0 are affected by GHSA-3343-386p-v26g. rubyzip now resolves to 3.7.0, and bundle-audit is clean on the resolved bundle. The other direct pins have no open advisories. I updated the description with details; the main caveat is that 0.6.x requires Ruby >= 3.0.

@lehors lehors left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, please!

@lehors

lehors commented Oct 5, 2026

Copy link
Copy Markdown

Thanks for putting this PR together @benbalter.
I'm surprised it is taking so long for this PR to be merged and a new release to be produced given the number of projects impacted with the high severity vulnerability this is addressing...

@benbalter

Copy link
Copy Markdown
Contributor Author

I'm surprised it is taking so long for this PR to be merged and a new release to be produced given the number of projects impacted with the high severity vulnerability this is addressing...

If you're interested, contacting GitHub support (or posting in the relevant community forum) would likely be the best path.

@lehors

lehors commented Oct 7, 2026

Copy link
Copy Markdown

I'm surprised it is taking so long for this PR to be merged and a new release to be produced given the number of projects impacted with the high severity vulnerability this is addressing...

If you're interested, contacting GitHub support (or posting in the relevant community forum) would likely be the best path.

Done (sent email to GitHub support).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2026-85396 rubyzip path traversal vulnerability

3 participants