Skip to content

Spree Commerce

v5.5.4 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 6d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

b2b-commerce e-commerce ecommerce ecommerce-api ecommerce-framework ecommerce-platform
+8 more
headless headless-commerce headless-ecommerce marketplace multi-tenant multi-vendor multi-vendor-ecommerce spree-commerce

Summary

AI summary

Security patch GHSA-4825-p4xm-pcf2 and two additional hardening improvements.

Full changelog

This release includes a security patch for GHSA-4825-p4xm-pcf2 plus two hardening security improvements

Updating

spree bundle update

Full Changelog: https://github.com/spree/spree/compare/v5.5.3...v5.5.4

Security Fixes

  • dep: GHSA-4825-p4xm-pcf2 — security patch for Spree Commerce
  • Hardening improvement #1 — unspecified details in changelog
  • Hardening improvement #2 — unspecified details in changelog

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Spree Commerce

Get notified when new releases ship.

Sign up free

About Spree Commerce

Spree is a complete, modular & API-driven open source e-commerce solution for Ruby on Rails.

All releases →

Related context

Beta — feedback welcome: [email protected]