Skip to content

chore(deps): update dependency nokogiri to v1.18.3 [security]#2485

Merged
jacopen merged 1 commit intomainfrom
renovate/rubygems-nokogiri-vulnerability
Mar 12, 2025
Merged

chore(deps): update dependency nokogiri to v1.18.3 [security]#2485
jacopen merged 1 commit intomainfrom
renovate/rubygems-nokogiri-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 19, 2025

✅ マイナーチェンジ以上のアップデートは動作確認をしてからマージすること

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
nokogiri '1.16.5' -> '1.18.3' age adoption passing confidence

GitHub Vulnerability Alerts

GHSA-vvfq-8hwr-qm4m

Summary

Nokogiri v1.18.3 upgrades its dependency libxml2 to v2.13.6.

libxml2 v2.13.6 addresses:

Impact

CVE-2025-24928

Stack-buffer overflow is possible when reporting DTD validation errors if the input contains a long (~3kb) QName prefix.

CVE-2024-56171

Use-after-free is possible during validation against untrusted XML Schemas (.xsd) and, potentially, validation of untrusted documents against trusted Schemas if they make use of xsd:keyref in combination with recursively defined types that have additional identity constraints.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Feb 19, 2025
@renovate renovate bot requested a review from a team February 19, 2025 05:41
@github-actions
Copy link

Simplecov Report

Covered Threshold
61.8% 60%

@renovate renovate bot force-pushed the renovate/rubygems-nokogiri-vulnerability branch from 9af1e8f to 8c22609 Compare March 3, 2025 17:46
@jacopen jacopen merged commit acd8b04 into main Mar 12, 2025
6 checks passed
@jacopen jacopen deleted the renovate/rubygems-nokogiri-vulnerability branch March 12, 2025 08:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant