DCgov / economic-intelligence

DMPED's EI Public Dashboard
http://open.dc.gov/economic-intelligence/
Other
9 stars 15 forks source link

Bump nokogiri from 1.6.6.2 to 1.6.6.4 #68

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps nokogiri from 1.6.6.2 to 1.6.6.4.

Changelog

Sourced from nokogiri's changelog.

1.6.6.4 / 2015-11-19

This version pulls in an upstream patch to the vendored libxml2 to address:

  • unclosed comment uninitialized access issue (#1376)

This issue was assigned CVE-2015-8710 after the fact. See http://seclists.org/oss-sec/2015/q4/616 for details.

1.6.6.3 / 2015-11-16

This version pulls in several upstream patches to the vendored libxml2 and libxslt to address:

  • CVE-2015-1819
  • CVE-2015-7941_1
  • CVE-2015-7941_2
  • CVE-2015-7942
  • CVE-2015-7942-2
  • CVE-2015-8035
  • CVE-2015-7995

See #1374 for details.

Commits
  • 2896e94 update CHANGELOG for v1.6.6.4
  • 6eda84f Version bump to v1.6.6.4
  • a070cc4 Moving latest patches into ports/patches.
  • 3ab1b23 Add patch for unclosed comment uninitialized access issue
  • f5b8e91 Version bump to v1.6.6.3
  • 83e0ede Update test_all with more recent rubies.
  • e93cd34 update Manifest.txt with latest patches
  • ebefeb6 Moving latest patches into ports/patches
  • ac6106f Add patch files for recently fixed vulnerabilities.
  • See full diff in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/DCgov/economic-intelligence/network/alerts).