Skip to content

Upgrade nokogiri to 1.19.3 to fix Dependabot security alerts#68

Merged
technicalpickles merged 1 commit into
mainfrom
nokgori-fixes
Jun 18, 2026
Merged

Upgrade nokogiri to 1.19.3 to fix Dependabot security alerts#68
technicalpickles merged 1 commit into
mainfrom
nokgori-fixes

Conversation

@technicalpickles

Copy link
Copy Markdown
Collaborator

This PR upgrades nokogiri from version 1.18.5 to 1.19.3 to address the following Dependabot security alerts:

The upgrade ensures we're using libxml2 v2.13.8 which resolves these security concerns.

This upgrade addresses CVE-2025-32414 and CVE-2025-32415 by updating nokogiri to version 1.19.3 which uses libxml2 v2.13.8.
@technicalpickles technicalpickles requested a review from a team as a code owner June 17, 2026 21:14
@github-project-automation github-project-automation Bot moved this to Triage in Modularity Jun 17, 2026
@technicalpickles technicalpickles enabled auto-merge (squash) June 17, 2026 21:15
@technicalpickles technicalpickles merged commit 2ff84ff into main Jun 18, 2026
6 checks passed
@technicalpickles technicalpickles deleted the nokgori-fixes branch June 18, 2026 16:20
@github-project-automation github-project-automation Bot moved this from Triage to Done in Modularity Jun 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants