Skip to content

GHSA/SYNC: Add 8 new nokogiri advisories.#1130

Merged
jasnow merged 1 commit into
rubysec:masterfrom
connorshea:nokogiri-cves
Jun 21, 2026
Merged

GHSA/SYNC: Add 8 new nokogiri advisories.#1130
jasnow merged 1 commit into
rubysec:masterfrom
connorshea:nokogiri-cves

Conversation

@connorshea

Copy link
Copy Markdown
Contributor

Added 8 new GHSA advisories from nokogiri using bundle exec rake "sync_github_advisories[nokogiri]":

Please tell me if there's anything in here that should be stripped out or added/modified. Also note that this was generated after my fix in #1129 so that CVSS v4 scores were pulled in. One advisory lacks a CVSS entirely and that is noted in its YML file.

@flavorjones flavorjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caveat, I wrote these advisories so somebody else should eyeball them too.

@flavorjones flavorjones requested a review from simi June 20, 2026 14:37
@jasnow

jasnow commented Jun 20, 2026

Copy link
Copy Markdown
Member

@flavorjones - Please add cvss_v4 to GHSA-wfpw-mmfh-qq69

@flavorjones

Copy link
Copy Markdown
Member

@jasnow sorry I'm not sure I understand what you're asking. I don't calculate cvss scores for library vulnerabilities in nokogiri as a matter of policy. Any cvss score for these was calculated by someone downstream.

@jasnow jasnow self-requested a review June 20, 2026 22:24

@jasnow jasnow left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I approve this PR.

Also I expect to:

  • I will change README to accept "|-".
  • I will reopen PR#1079 to check desc line width (<= 80).
    I will fix regressions.

@jasnow jasnow merged commit 352c185 into rubysec:master Jun 21, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants