Skip to content

LIBSCHOLAR-63 Update .bundler-audit.yml file to current vulnerabilities#1194

Open
Janell-Huyck wants to merge 1 commit intodevelopfrom
LIBSCHOLAR-63-update-bundler-audit-ignore-list-so-that-current-p-rs-can-get-merged
Open

LIBSCHOLAR-63 Update .bundler-audit.yml file to current vulnerabilities#1194
Janell-Huyck wants to merge 1 commit intodevelopfrom
LIBSCHOLAR-63-update-bundler-audit-ignore-list-so-that-current-p-rs-can-get-merged

Conversation

@Janell-Huyck
Copy link
Contributor

@Janell-Huyck Janell-Huyck commented Feb 4, 2026

Update bundler-audit ignore list for current vulnerabilities

Summary

Updates .bundler-audit.yml so the current bundler-audit findings are explicitly ignored, allowing PRs to merge while the team plans gem upgrades.

Changes

  • New ignore entries — Added all CVEs and GHSAs reported by the latest bundler-audit run (Rails 5.2, nokogiri, rack, puma, httparty, carrierwave, devise, and others).
  • New gem sections — Added ignore blocks for: actionmailer, activesupport, aws-sdk-s3, carrierwave, devise, globalid, httparty, jquery-ui-rails, puma, sidekiq, thor.
  • Existing sections — Kept existing ignores and merged in any new advisories for: actionpack, actionview, activerecord, activestorage, loofah, nokogiri, omniauth, rack, rails-html-sanitizer, rexml, webrick.
  • Comments — Section comments now include the affected version (where known) and the recommended fix version(s) from advisories (e.g. fix: >= 1.4.4) so future upgrades are easier to plan.
  • Organization — Sections are grouped by gem and sorted alphabetically; both CVE and GHSA IDs are listed so the ignore list matches bundler-audit output.

Notes

  • This is a temporary measure so CI (and PRs) can pass; the comments in the file document the versions needed to actually fix each finding.

  • Addressing these will require upgrading gems (notably Rails and related stack) to the versions noted in the comments; that should be tracked and done in a follow-up.

  • Bjorg has been notified of this action.

Related

  • LIBSCHOLAR-63

@scherztc scherztc self-assigned this Feb 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants