Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-r58r-74gx-6wx3] Nokogiri gem, via libxml, is affected by DoS vulnerabilities #2667

Closed
wants to merge 1 commit into from

Conversation

dgm
Copy link

@dgm dgm commented Aug 27, 2023

Updates

  • Affected products

Comments
The current version of Nokogiri is 1.15.4 so it's impossible to upgrade to 2.9.6. Nokogiri addressed this dependency in version 1.8.2. The stated version number of 2.9.5 applies to libxml, not Nokogiri, so you can't compare them. I suspect this is a duplicate rule anyway and already covered, but this rule triggered a large number of dependabot false positives.

@github-actions github-actions bot changed the base branch from main to dgm/advisory-improvement-2667 August 27, 2023 18:34
@chadlwilson
Copy link
Contributor

#2660 has been merged so hopefully this is fixed soon

@dgm
Copy link
Author

dgm commented Aug 28, 2023

Yep, looks like a lot of duplicates at about the same time. I've seen several of these kinds of alerts lately where the wrong gem gets flagged just because it was bundled with something else - something needs to be improved with the approval process. Duplicate of #2660

@dgm dgm closed this Aug 28, 2023
@github-actions github-actions bot deleted the dgm-GHSA-r58r-74gx-6wx3 branch August 28, 2023 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants