Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): Require at least nokogiri 1.16.2 to avoid CVE-2024-25062 #34

Closed
wants to merge 133 commits into from

Conversation

itsmechlark
Copy link
Contributor

No description provided.

dependabot bot and others added 27 commits January 27, 2024 02:11
Bumps [ruby-lsp](https://github.com/Shopify/ruby-lsp) from 0.9.4 to 0.13.4.
- [Release notes](https://github.com/Shopify/ruby-lsp/releases)
- [Commits](Shopify/ruby-lsp@v0.9.4...v0.13.4)

---
updated-dependencies:
- dependency-name: ruby-lsp
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
….13.4

feat(deps): bump ruby-lsp from 0.9.4 to 0.13.4
Bumps [sqlite3](https://github.com/sparklemotion/sqlite3-ruby) from 1.6.4 to 1.7.1.
- [Release notes](https://github.com/sparklemotion/sqlite3-ruby/releases)
- [Changelog](https://github.com/sparklemotion/sqlite3-ruby/blob/main/CHANGELOG.md)
- [Commits](sparklemotion/sqlite3-ruby@v1.6.4...v1.7.1)

---
updated-dependencies:
- dependency-name: sqlite3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
feat(deps): bump sqlite3 from 1.6.4 to 1.7.1
…, < 2.10

Updates the requirements on [faraday](https://github.com/lostisland/faraday) to permit the latest version.
- [Release notes](https://github.com/lostisland/faraday/releases)
- [Changelog](https://github.com/lostisland/faraday/blob/main/CHANGELOG.md)
- [Commits](lostisland/faraday@v2.7.10...v2.9.0)

---
updated-dependencies:
- dependency-name: faraday
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
feat(deps): update faraday requirement from >= 1.10, < 2.8 to >= 1.10, < 2.10
Bumps [google-github-actions/release-please-action](https://github.com/google-github-actions/release-please-action) from 3 to 4.
- [Release notes](https://github.com/google-github-actions/release-please-action/releases)
- [Changelog](https://github.com/google-github-actions/release-please-action/blob/main/CHANGELOG.md)
- [Commits](google-github-actions/release-please-action@v3...v4)

---
updated-dependencies:
- dependency-name: google-github-actions/release-please-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…gle-github-actions/release-please-action-4

ci(deps): Bump google-github-actions/release-please-action from 3 to 4
Bumps [auth0](https://github.com/auth0/ruby-auth0) from 5.14.1 to 5.16.0.
- [Release notes](https://github.com/auth0/ruby-auth0/releases)
- [Changelog](https://github.com/auth0/ruby-auth0/blob/master/CHANGELOG.md)
- [Commits](auth0/ruby-auth0@v5.14.1...v5.16.0)

---
updated-dependencies:
- dependency-name: auth0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
feat(deps): Bump auth0 from 5.14.1 to 5.16.0
Bumps [rails](https://github.com/rails/rails) from `90b0266` to `517ff4b`.
- [Release notes](https://github.com/rails/rails/releases)
- [Commits](rails/rails@90b0266...517ff4b)

---
updated-dependencies:
- dependency-name: rails
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
feat(deps): bump rails from `90b0266` to `517ff4b`
Bumps [devise](https://github.com/heartcombo/devise) from 4.9.2 to 4.9.3.
- [Release notes](https://github.com/heartcombo/devise/releases)
- [Changelog](https://github.com/heartcombo/devise/blob/main/CHANGELOG.md)
- [Commits](heartcombo/devise@v4.9.2...v4.9.3)

---
updated-dependencies:
- dependency-name: devise
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
feat(deps): Bump devise from 4.9.2 to 4.9.3
…n--components--devise_auth0

chore(main): release 1.2.1
@itsmechlark itsmechlark requested a review from a team February 13, 2024 04:36
@itsmechlark itsmechlark changed the title fix(deps): Fix CVE 2024 25062 fix(deps): Require at least nokogiri 1.16.2 to avoid CVE-2024-25062 Feb 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

1 participant