Skip to content

Add nekohtml advisory based on nokogiri advisory#1084

Closed
jasnow wants to merge 1 commit into
rubysec:masterfrom
jasnow:new-nekohtml-advisory
Closed

Add nekohtml advisory based on nokogiri advisory#1084
jasnow wants to merge 1 commit into
rubysec:masterfrom
jasnow:new-nekohtml-advisory

Conversation

@jasnow
Copy link
Copy Markdown
Member

@jasnow jasnow commented May 30, 2026

Add nekohtml advisory based on nokogiri advisory

@flavorjones
Copy link
Copy Markdown
Collaborator

I personally don't think it's necessary to create this file.

  1. The Nokogiri fork of nekohtml is not available as a ruby gem.
  2. It is ONLY vendored in Nokogiri, and gems/nokogiri/CVE-2022-24839.yml already exists to notify people to upgrade Nokogiri.

So I don't know who's going to use this information, or how it will be actionable.

I recommend closing without merging, but will defer to the other maintainers if they feel strongly it should be part of the record.

@jasnow
Copy link
Copy Markdown
Member Author

jasnow commented May 31, 2026

Based on @flavorjones and @simi feedback, I will closing this PR.

@jasnow jasnow closed this May 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants