Skip to content

Conversation

@aried3r
Copy link
Contributor

@aried3r aried3r commented Feb 18, 2020

No description provided.

@kwent
Copy link

kwent commented Jan 2, 2021

@soundasleep Please merge. This is fixing a critical vulnerability: GHSA-vr8q-g5c7-m54m

@krtschmr
Copy link

krtschmr commented Jan 5, 2021

only question is: should we force 1.11 to be the minimum?

@aried3r
Copy link
Contributor Author

aried3r commented Jan 5, 2021

Nokogiri 1.11 ist 2 days old and ends support for Ruby 2.3 and 2.4.

There might be users that use this project or nokogiri itself in ways that is safe enough for them, given the vulnerability.

I'd say, allow people to update, but don't force this version, at least for now.

https://github.com/sparklemotion/nokogiri/blob/master/CHANGELOG.md#v1110--2021-01-03

WDYT?

@krtschmr
Copy link

krtschmr commented Jan 5, 2021

That's actually a fair argument. We run 2.7 so we can force 1.11. I opened a pull request earlier today where we use 1.11, then saw yours and just asked why, but i never thought about older versions ;-)

Seems like owner abandoned this project. The classy fail of github opensource somehow. sad.

i dobut this gets merged :/

@baburdick
Copy link

When the new maintainers revive this project, please close this in favor of #16 or #17.

@mscrivo
Copy link
Collaborator

mscrivo commented Jun 7, 2024

Resolved in #17

@mscrivo mscrivo closed this Jun 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants