projecttacoma / cqm-parsers

This project contains libraries for parsing HQMF documents and parsing MAT packages.
Apache License 2.0
5 stars 3 forks source link

Bump Nokogiri to Resolve CVE-2021-41098 (bonnie-on-fhir) #161

Closed jkotanchik-SB closed 3 years ago

jkotanchik-SB commented 3 years ago

Bump Nokogiri to 1.12.5 to resolve security vuln. See Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby for more info.

This bump may not be needed since the vulnerability is currently reported to only affect JRuby.

Pull requests into cqm-parsers require the following. Submitter and reviewer should :white_check_mark: when done. For items that are not-applicable, note it's not-applicable ("N/A") and :white_check_mark:.

Submitter:

Reviewer 1:

Name:

Reviewer 2:

Name: