Fix patched version for nokogiri (GHSA-2qc6-mcvw-92cw)#519
Fix patched version for nokogiri (GHSA-2qc6-mcvw-92cw)#519reedloden merged 1 commit intorubysec:masterfrom
Conversation
GHSA-2qc6-mcvw-92cw is reported to be fixed by 1.13.9+, not 1.13.19.
|
Please merge this, as it is breaking our audit step in our build |
|
Can this please be merged soon? I'm sure we are not the only ones having issues with their CI/CD yelling at them about failing bundle audits because of this issue. |
|
Merge, please! 🙏🏻 Let this be a lesson in why you don't release shit immediately before signing off for the day 🤣 |
|
cc @reedloden @postmodern This is blocking CI for lots of people, it should be a trivial review/merge. |
|
Fyi: We could ignore this CVE to unblock CI until this gets merged |
We have tried that. Not sure if it's an issue with our build system but it's not working. |
This worked for us on circleci FWIW: |
It also did not work for me until I updated the bundler-audit gem |
|
Apologies to all for my typo! Sorry to any extra work this may have caused folks. |
|
@reedloden Would it be helpful in the future if I shipped a PR here for the inevitable next nokogiri/libxml2 GHSA? Happy to do it, I've got a release checklist. |
|
@reedloden It's okay :) We all make mistakes. Thank you for your diligence on maintaining this repo. |
Yes, please. That would be amazing! |
|
I bet we could add additional linter tests to check that every |
GHSA-2qc6-mcvw-92cw is reported to be fixed by 1.13.9+, not 1.13.19.