Package
gitlab-rails-ce-fips-19.1
Component
doorkeeper-openid_connect
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
GitLab bundles doorkeeper-openid_connect 1.9.0 via its Gemfile.lock; the fix is in 1.10.0 (GHSA-m6vc-f87m-cc2h), but GitLab's Gemfile pins '~> 1.9.0', capping below 1.10.0. The fix cannot be applied without GitLab relaxing this constraint upstream. Per GitLab's dependency policy, dependencies are not upgraded manually ahead of upstream, and prior manual bumps of GitLab gems have caused build failures. Deferring to upstream (GitLab) to adopt doorkeeper-openid_connect >= 1.10.0. See: https://docs.gitlab.com/ee/development/dependencies.html
Status