Skip to content

Security: bump actionview, activesupport, nokogiri, uri, yard#30

Draft
technicalpickles wants to merge 1 commit into
mainfrom
security/dep-sweep
Draft

Security: bump actionview, activesupport, nokogiri, uri, yard#30
technicalpickles wants to merge 1 commit into
mainfrom
security/dep-sweep

Conversation

@technicalpickles

Copy link
Copy Markdown
Contributor

Summary

Security update addressing multiple CVEs across 5 gems.

Gem Old New GHSA Severity
actionview 8.0.2 8.1.3 GHSA-v55j-83pf-r9cq -
activesupport 8.0.2 8.1.3 GHSA-2j26-frm8-cmj9, GHSA-89vf-4333-qx8v, GHSA-cg4j-q9v8-6v38 -
nokogiri 1.18.5 1.19.4 GHSA-v2fc-qm4h-8hqv, GHSA-c4rq-3m3g-8wgx, GHSA-wx95-c6cv-8532, GHSA-353f-x4gh-cqq8, GHSA-5w6v-399v-w3cc -
uri 1.0.3 1.1.1 GHSA-j4pr-3wm6-xx2r -
yard 0.9.37 0.9.44 GHSA-3jfp-46x4-xgfj -

Note: No major-version bumps — all updates are within the same major version series (Rails 8.x, nokogiri 1.x).

Testing

  • rspec: 60 examples, 0 failures
  • rubocop: all checks passing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Triage

Development

Successfully merging this pull request may close these issues.

1 participant