Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update nokogiri to 1.11 #473

Merged
merged 1 commit into from
Jan 14, 2021
Merged

Update nokogiri to 1.11 #473

merged 1 commit into from
Jan 14, 2021

Conversation

ashin-omg
Copy link
Contributor

Nokogiri < 1.11 is vulnerable to XML External Entity (XXE) Injection
https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1055008

Nokogiri < 1.11 is vulnerable to XML External Entity (XXE) Injection 
https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1055008
@ashin-omg ashin-omg changed the title Update nokogiri Update nokogiri to 1.11 Jan 5, 2021
@coveralls
Copy link

Coverage Status

Coverage remained the same at 95.558% when pulling da077e5 on ashin-omg:patch-1 into 2c336ee on SlatherOrg:master.

@matcartmill
Copy link

matcartmill commented Jan 7, 2021

@ksuther can this get reviewed when you have a moment? My security team gets a digest of all issues reported and this one is flagged. Would love to tell them it's in progress.

Thanks.

@danl3v
Copy link

danl3v commented Jan 7, 2021

This would be great to have in. Thanks!

@matcartmill
Copy link

@ksuther can we get an update please?

@ksuther ksuther merged commit a78e1ef into SlatherOrg:master Jan 14, 2021
@ksuther
Copy link
Contributor

ksuther commented Jan 14, 2021

Thanks for the PR! I'll make a new release in the next week or so as well.

@ashin-omg ashin-omg deleted the patch-1 branch January 15, 2021 21:06
This was referenced Mar 8, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants