Skip to content

Commit 4b9bfe3

Browse files
committed
update CHANGELOG with the GHSA
and markdown links to issues.
1 parent 9d69b44 commit 4b9bfe3

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

CHANGELOG.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,9 @@ Nokogiri follows [Semantic Versioning](https://semver.org/), please see the [REA
1717
- [CVE-2021-3537](https://security.archlinux.org/CVE-2021-3537)
1818
- [CVE-2021-3541](https://security.archlinux.org/CVE-2021-3541)
1919

20-
Note that two additional CVEs were addressed upstream but are not relevant to this release. [CVE-2021-3516](https://security.archlinux.org/CVE-2021-3516) via `xmllint` is not present in Nokogiri, and [CVE-2020-7595](https://security.archlinux.org/CVE-2020-7595) has been patched in Nokogiri since v1.10.8 (see #1992).
20+
Note that two additional CVEs were addressed upstream but are not relevant to this release. [CVE-2021-3516](https://security.archlinux.org/CVE-2021-3516) via `xmllint` is not present in Nokogiri, and [CVE-2020-7595](https://security.archlinux.org/CVE-2020-7595) has been patched in Nokogiri since v1.10.8 (see [#1992](https://github.com/sparklemotion/nokogiri/issues/1992)).
2121

22-
Please see #2233 for a more complete analysis of these CVEs and patches.
22+
Please see [nokogiri/GHSA-7rrm-v45f-jp64 ](https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-7rrm-v45f-jp64) or [#2233](https://github.com/sparklemotion/nokogiri/issues/2233) for a more complete analysis of these CVEs and patches.
2323

2424

2525
### Dependencies

0 commit comments

Comments
 (0)