Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Update gem nokogiri from 1.6.7.2 to version 1.6.8. This update was reported to us by our usual bundle-audit dependency analysis process (part of the default 'rake' process), It reported that nokogiri 1.6.7.2 had advisory CVE-2015-8806, title "Denial of service or RCE from libxml2 and libxslt". We don't know if it's exploitable in our configuration, but it's better to upgrade than do the analysis. Those interested can see more at: sparklemotion/nokogiri#1473 This caused us to upgrade pkg-config, which required a licensing decision (included in the commit). This whitelists LGPLv2+, since that's a known OSI license that's compatible with the MIT license. Signed-off-by: David A. Wheeler <[email protected]>
- Loading branch information