chef-server
chef-server copied to clipboard
Bump nokogiri from 1.14.3 to 1.16.2 in /src/oc-id
Bumps nokogiri from 1.14.3 to 1.16.2.
Release notes
Sourced from nokogiri's releases.
v1.16.2 / 2024-02-04
Security
- [CRuby] Vendored libxml2 is updated to address CVE-2024-25062. See GHSA-xc9x-jj77-9p9j for more information.
Dependencies
- [CRuby] Vendored libxml2 is updated to v2.12.5 from v2.12.4. (
@flavorjones)
sha256 checksums:
69ba15d2a2498324489ed63850997f0b8f684260114ea81116d3082f16551d2d nokogiri-1.16.2-aarch64-linux.gem 6a05ce42e3587a40cf8936ece0beaa5d32922254215d2e8cf9ad40588bb42e57 nokogiri-1.16.2-arm-linux.gem c957226c8e36b31be6a3afb8602e2128282bf8b40ea51016c4cd21aa2608d3f8 nokogiri-1.16.2-arm64-darwin.gem 122652bfc338cd8a54a692ac035e245e41fd3b8283299202ca26e7a7d50db310 nokogiri-1.16.2-java.gem 7344b5072ca69fc5bedb61cb01a3b765b93a27aae5a2a845c2ba7200e4345074 nokogiri-1.16.2-x64-mingw-ucrt.gem a2a5e184a424111a0d5b77947986484920ad708009c667f061e8d02035c562dd nokogiri-1.16.2-x64-mingw32.gem 833efddeb51a6c2c9f6356295623c2b2e0d50050d468695c59bd929162953323 nokogiri-1.16.2-x86-linux.gem e67fc0418dffaff9dc8b1dc65f0605282c3fee9488832d0223b620b4319e0b53 nokogiri-1.16.2-x86-mingw32.gem 5def799e5f139f21a79d7cf71172313a7b6fb0e4b2a31ab9bd5d4ad305994539 nokogiri-1.16.2-x86_64-darwin.gem 5b146240ac6ec6c40fd4367623e74442bca45a542bd3282b1d4d18b07b8e5dfe nokogiri-1.16.2-x86_64-linux.gem 68922ee5cde27497d995c46f2821957bae961947644eed2822d173daf7567f9c nokogiri-1.16.2.gemv1.16.1 / 2024-02-03
Dependencies
- [CRuby] Vendored libxml2 is updated to v2.12.4 from v2.12.3. (
@flavorjones)Fixed
- [CRuby]
XML::Readerdefaults the encoding to UTF-8 if it's not specified in either the document or as a method parameter. Previously non-ASCII characters were serialized as NCRs in this case. #2891 (@flavorjones)- [CRuby] Restored support for compilation by GCC versions earlier than 4.6, which was broken in v1.15.0 (540e9aee). #3090 (
@adfoster-r7)- [CRuby] Patched upstream libxml2 to allow parsing HTML5 in the context of a namespaced node (e.g., foreign content like MathML). [#3112, #3116] (
@flavorjones)- [CRuby] Fixed a small memory leak in libgumbo (HTML5 parser) when the maximum tree depth limit is hit. [#3098, #3100] (
@stevecheckoway)
sha256 checksums:
a541f35e5b9798a0c97300f9ee18f4217da2a2945a6d5499e4123b9018f9cafc nokogiri-1.16.1-aarch64-linux.gem 6b82affd195000ab2f9c36cc08744ec2d2fcf6d8da88d59a2db67e83211f7c69 nokogiri-1.16.1-arm-linux.gem </tr></table>
... (truncated)
Changelog
Sourced from nokogiri's changelog.
v1.16.2 / 2024-02-04
Security
- [CRuby] Vendored libxml2 is updated to address CVE-2024-25062. See GHSA-xc9x-jj77-9p9j for more information.
Dependencies
- [CRuby] Vendored libxml2 is updated to v2.12.5 from v2.12.4. (
@flavorjones)v1.16.1 / 2024-02-03
Dependencies
- [CRuby] Vendored libxml2 is updated to v2.12.4 from v2.12.3. (
@flavorjones)Fixed
- [CRuby]
XML::Readerdefaults the encoding to UTF-8 if it's not specified in either the document or as a method parameter. Previously non-ASCII characters were serialized as NCRs in this case. #2891 (@flavorjones)- [CRuby] Restored support for compilation by GCC versions earlier than 4.6, which was broken in v1.15.0 (540e9aee). #3090 (
@adfoster-r7)- [CRuby] Patched upstream libxml2 to allow parsing HTML5 in the context of a namespaced node (e.g., foreign content like MathML). [#3112, #3116] (
@flavorjones)- [CRuby] Fixed a small memory leak in libgumbo (HTML5 parser) when the maximum tree depth limit is hit. [#3098, #3100] (
@stevecheckoway)v1.16.0 / 2023-12-27
Notable Changes
Ruby
This release introduces native gem support for Ruby 3.3.
This release ends support for Ruby 2.7, for which upstream support ended 2023-03-31.
Pattern matching
This version marks official support for the pattern matching API in
XML::Attr,XML::Document,XML::DocumentFragment,XML::Namespace,XML::Node, andXML::NodeSet(and their subclasses), originally introduced as an experimental feature in v1.14.0. (@flavorjones)Documentation on what can be matched:
... (truncated)
Commits
673756fversion bump to v1.16.274ffd67dep: update libxml to 2.12.5 (branch v1.16.x) (#3122)0d4018ddep: update libxml2 to v2.12.5f33a25fdep: remove patch from #3112 which has been released upstreame994168version bump to v1.16.177ea2f2dev: add files to manifest ignore list756f27cbuild(deps): bump actions/{download,upload}-artifact from 3 to 4464f8d4.gitignore: clangd-related files2beeb96doc: update CHANGELOGa26536dfix: apply upstream patch for in-context parsing (#3116)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Deploy Preview for chef-server processing.
| Name | Link |
|---|---|
| Latest commit | 5b7f3077dfe4ae1b8c3aff3ccc79b93dffa169eb |
| Latest deploy log | https://app.netlify.com/sites/chef-server/deploys/66014d0c04f1080008c0b4ed |
Quality Gate passed
Kudos, no new issues were introduced!
0 New issues
0 Security Hotspots
No data about Coverage
No data about Duplication
Quality Gate passed
Issues
0 New issues
0 Accepted issues
Measures
0 Security Hotspots
No data about Coverage
No data about Duplication
Adhoc: https://buildkite.com/chef/chef-chef-server-main-omnibus-adhoc/builds/6222 Umbrella: https://buildkite.com/chef/chef-umbrella-main-chef-server/builds/2462
A newer version of nokogiri exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.







