From 3f7bab9a162619ba7c1a3bb183c0db806a088ac1 Mon Sep 17 00:00:00 2001 From: Janell-Huyck Date: Mon, 7 Apr 2025 12:48:14 -0400 Subject: [PATCH 1/2] Add GHSA-mrxw-mxhj-p-664 to bundler audit ignore list --- .bundler-audit.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.bundler-audit.yml b/.bundler-audit.yml index b97cd544..84fb4934 100644 --- a/.bundler-audit.yml +++ b/.bundler-audit.yml @@ -6,8 +6,10 @@ ignore: - CVE-2024-53986 - CVE-2024-53985 - # actionpack - needs Rails 7 upgrade to fix + # actionpack - needs Rails 7 upgrade to fix - CVE-2024-54133 - # Nokogiri - servers don't have compatible GLIBC + # Nokogiri - servers don't have compatible GLIBC. + # Need to upgrade to nokogiri version 1.18 to fix these. - GHSA-vvfq-8hwr-qm4m + - GHSA-mrxw-mxhj-p-664 From eb6b0f1af8b3c0354e981d14572877110669a38d Mon Sep 17 00:00:00 2001 From: Janell-Huyck Date: Mon, 7 Apr 2025 12:55:47 -0400 Subject: [PATCH 2/2] Correct error number put into .bundler-audit.yml file --- .bundler-audit.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.bundler-audit.yml b/.bundler-audit.yml index 84fb4934..a2c2e85e 100644 --- a/.bundler-audit.yml +++ b/.bundler-audit.yml @@ -12,4 +12,4 @@ ignore: # Nokogiri - servers don't have compatible GLIBC. # Need to upgrade to nokogiri version 1.18 to fix these. - GHSA-vvfq-8hwr-qm4m - - GHSA-mrxw-mxhj-p-664 + - GHSA-mrxw-mxhj-p664