Skip to content

Conversation

@RalphHightower
Copy link
Owner

No description provided.

@RalphHightower RalphHightower self-assigned this Jul 23, 2025
@RalphHightower RalphHightower added security Security Issue config – Ruby Ruby configuration labels Jul 23, 2025
@RalphHightower RalphHightower linked an issue Jul 23, 2025 that may be closed by this pull request
@github-actions
Copy link

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
rubygems/nokogiri ~> 1.18,>= 1.18.9 🟢 6.5
Details
CheckScoreReason
Security-Policy🟢 10security policy file detected
Code-Review⚠️ 2Found 2/10 approved changesets -- score normalized to 2
Maintained🟢 1025 commit(s) and 9 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices🟢 5badge detected: Passing
License🟢 10license file detected
Vulnerabilities🟢 100 existing vulnerabilities detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases⚠️ -1no releases found
Binary-Artifacts⚠️ 1binaries present in source code
Fuzzing🟢 10project is fuzzed
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Packaging🟢 10packaging workflow detected
SAST🟢 9SAST tool is not run on all commits -- score normalized to 9
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0

Scanned Files

  • Gemfile

@RalphHightower RalphHightower changed the title [upgrade](sec): GitHub Security Advisory [upgrade](sec): GitHub Security Advisory: GHSA-353f-x4gh-cqq8 Rubygem(Nokogiri) #1740 Jul 23, 2025
@RalphHightower RalphHightower merged commit 48923f4 into main Jul 23, 2025
6 of 10 checks passed
@RalphHightower RalphHightower added the action – success Successful action label Aug 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action – success Successful action config – Ruby Ruby configuration security Security Issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GHSA-353f-x4gh-cqq8 Rubygem(Nokogiri)

2 participants