[Security] Bump nokogiri from 1.8.0 to 1.8.2 #78
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps nokogiri from 1.8.0 to 1.8.2. This update includes security fixes.
Vulnerabilities fixed
Changelog
Sourced from nokogiri's changelog.
Commits
f80f4ad
version bump to 1.8.2d35ed46
update CHANGELOG62b1a5b
update CHANGELOG6e14afe
Merge pull request #1713 from sparklemotion/flavorjones-1238-segfault-reparen...b1494e5
ensure EntityReferences ignore malformed childrend3456e4
update CHANGELOGbf94cf5
remove hacks to discover the path toracc
734d4d4
Merge pull request #1704 from larskanis/win-ruby-2.5cc80904
Appveyor: Add ruby-2.4 and ruby-head to build matrix992d81b
Windows: Add cross build for ruby-2.5Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot ignore this [minor|major] version
will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use [this|these] label[s]
will set the current labels as the default for future PRs for this repo and languageAdditionally, you can set the following in your Dependabot dashboard:
Finally, you can contact us by mentioning @dependabot.