{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":203484163,"defaultBranch":"main","name":"nzsl-share","ownerLogin":"ackama","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2019-08-21T01:44:11.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/1941990?v=4","public":true,"private":false,"isOrgOwned":true},"refInfo":{"name":"","listCacheKey":"v0:1721178055.0","currentOid":""},"activityList":{"items":[{"before":null,"after":"e29105bb9e72a6ae225250194ce148f7ad4059e5","ref":"refs/heads/update-rexml","pushedAt":"2024-07-17T01:00:55.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"fix: update `rexml` for security\n\nAddresses GHSA-4xqq-m2hx-25v8","shortMessageHtmlLink":"fix: update rexml for security"}},{"before":"f05d44d8279231fe0173d9b0bdd611ee1007cad7","after":null,"ref":"refs/heads/upgrade-lighthouse","pushedAt":"2024-06-19T02:00:15.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"}},{"before":"9e51bcea0703547077247642f4a00b0351e7a3a6","after":"f2bcfb0565535fa8200a369baf6b8ecdb36a7f79","ref":"refs/heads/main","pushedAt":"2024-06-19T02:00:14.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"ci: upgrade `lighthouse` to v10 (#641)\n\nNewer versions of lighthouse are always better and this helps ensure we\r\ncan apply the latest security patches - we can't go any higher than v10\r\nright now because v11 required Node v18 or higher but this is still an\r\nimprovement and we plan to upgrade Node later this year","shortMessageHtmlLink":"ci: upgrade lighthouse to v10 (#641)"}},{"before":null,"after":"f05d44d8279231fe0173d9b0bdd611ee1007cad7","ref":"refs/heads/upgrade-lighthouse","pushedAt":"2024-06-19T01:27:17.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"ci: upgrade `lighthouse` to v10","shortMessageHtmlLink":"ci: upgrade lighthouse to v10"}},{"before":"87a927194872b1fb8978342c610b59d99acbb0b7","after":"cb0b486fec157bb182a9bcc2aea23f1fe04891f8","ref":"refs/heads/production","pushedAt":"2024-06-09T20:34:37.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"Merge pull request #640 from ackama/main\n\nstaging -> production","shortMessageHtmlLink":"Merge pull request #640 from ackama/main"}},{"before":"df1172bc0c626ab2b7aa796ca6e252ce0e5f7788","after":null,"ref":"refs/heads/dependabot/bundler/actionpack-7.1.3.4","pushedAt":"2024-06-09T20:13:25.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"}},{"before":"25c0627e2b04cc36e130475d4b87fab94f09b516","after":null,"ref":"refs/heads/update-rails","pushedAt":"2024-06-09T20:12:39.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"}},{"before":"2735cd646d6b5ef5b101cd345e7e015b13912da0","after":"9e51bcea0703547077247642f4a00b0351e7a3a6","ref":"refs/heads/main","pushedAt":"2024-06-09T20:12:38.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"fix: update `rails` for security (#639)\n\nIn addition to updating Rails, I've also locked it to v7.0.x so that\r\nfuture security updates (including those opened by dependabot) don't try\r\nto upgrade us to Rails v7.1, which is why #637 is failing\r\n\r\nAddresses GHSA-fwhr-88qx-h9g7\r\nAddresses GHSA-qjqp-xr96-cj99","shortMessageHtmlLink":"fix: update rails for security (#639)"}},{"before":null,"after":"25c0627e2b04cc36e130475d4b87fab94f09b516","ref":"refs/heads/update-rails","pushedAt":"2024-06-09T19:37:55.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"fix: update `rails` for security\n\nAddresses GHSA-fwhr-88qx-h9g7\nAddresses GHSA-qjqp-xr96-cj99","shortMessageHtmlLink":"fix: update rails for security"}},{"before":"2d159b94d673e66a9ecbffc7351436cc7eba15a7","after":"df1172bc0c626ab2b7aa796ca6e252ce0e5f7788","ref":"refs/heads/dependabot/bundler/actionpack-7.1.3.4","pushedAt":"2024-06-06T02:17:56.000Z","pushType":"force_push","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"Bump actionpack from 7.0.8.1 to 7.1.3.4\n\nBumps [actionpack](https://github.com/rails/rails) from 7.0.8.1 to 7.1.3.4.\n- [Release notes](https://github.com/rails/rails/releases)\n- [Changelog](https://github.com/rails/rails/blob/v7.1.3.4/actionpack/CHANGELOG.md)\n- [Commits](https://github.com/rails/rails/compare/v7.0.8.1...v7.1.3.4)\n\n---\nupdated-dependencies:\n- dependency-name: actionpack\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"Bump actionpack from 7.0.8.1 to 7.1.3.4"}},{"before":"00906f43cb50e5aea1da146d671df67ccb7e351c","after":null,"ref":"refs/heads/nzlaura-patch-1","pushedAt":"2024-06-06T02:15:25.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"nzlaura","name":"Laura Corkin","path":"/nzlaura","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/57056459?s=80&v=4"}},{"before":"02831ed804ad88533345c64b5a23d56c4c0a51a1","after":"2735cd646d6b5ef5b101cd345e7e015b13912da0","ref":"refs/heads/main","pushedAt":"2024-06-06T02:15:25.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"nzlaura","name":"Laura Corkin","path":"/nzlaura","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/57056459?s=80&v=4"},"commit":{"message":"chore: ignore unpatchable ip vulnerability (#638)\n\nCurrently there is no patch for the security advisory\r\nhttps://github.com/advisories/GHSA-2p57-rm9w-gvfp","shortMessageHtmlLink":"chore: ignore unpatchable ip vulnerability (#638)"}},{"before":null,"after":"00906f43cb50e5aea1da146d671df67ccb7e351c","ref":"refs/heads/nzlaura-patch-1","pushedAt":"2024-06-06T02:04:32.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"nzlaura","name":"Laura Corkin","path":"/nzlaura","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/57056459?s=80&v=4"},"commit":{"message":"chore: ignore unpatchable ip vulnerability","shortMessageHtmlLink":"chore: ignore unpatchable ip vulnerability"}},{"before":null,"after":"2d159b94d673e66a9ecbffc7351436cc7eba15a7","ref":"refs/heads/dependabot/bundler/actionpack-7.1.3.4","pushedAt":"2024-06-04T23:15:05.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"Bump actionpack from 7.0.8.1 to 7.1.3.4\n\nBumps [actionpack](https://github.com/rails/rails) from 7.0.8.1 to 7.1.3.4.\n- [Release notes](https://github.com/rails/rails/releases)\n- [Changelog](https://github.com/rails/rails/blob/v7.1.3.4/actionpack/CHANGELOG.md)\n- [Commits](https://github.com/rails/rails/compare/v7.0.8.1...v7.1.3.4)\n\n---\nupdated-dependencies:\n- dependency-name: actionpack\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"Bump actionpack from 7.0.8.1 to 7.1.3.4"}},{"before":"e289b9a25b1aa539927c9693621ca30cc50f2075","after":"87a927194872b1fb8978342c610b59d99acbb0b7","ref":"refs/heads/production","pushedAt":"2024-05-23T01:41:48.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"Merge pull request #636 from ackama/main\n\nStaging -> Production","shortMessageHtmlLink":"Merge pull request #636 from ackama/main"}},{"before":"792d6d88d0f2373df29aa437e1f0e71595024a2e","after":null,"ref":"refs/heads/dependabot/bundler/rexml-3.2.8","pushedAt":"2024-05-20T22:58:02.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"nzlaura","name":"Laura Corkin","path":"/nzlaura","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/57056459?s=80&v=4"}},{"before":"51e2b026fa35236c6d1362155c436cea62de9468","after":"02831ed804ad88533345c64b5a23d56c4c0a51a1","ref":"refs/heads/main","pushedAt":"2024-05-20T22:58:01.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"nzlaura","name":"Laura Corkin","path":"/nzlaura","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/57056459?s=80&v=4"},"commit":{"message":"Bump rexml from 3.2.5 to 3.2.8 (#635)\n\nBumps [rexml](https://github.com/ruby/rexml) from 3.2.5 to 3.2.8.\r\n
\r\nRelease notes\r\n

Sourced from rexml's\r\nreleases.

\r\n
\r\n

REXML 3.2.8 - 2024-05-16

\r\n

Fixes

\r\n
    \r\n
  • Suppressed a warning
  • \r\n
\r\n

REXML 3.2.7 - 2024-05-16

\r\n

Improvements

\r\n
    \r\n
  • \r\n

    Improve parse performance by using StringScanner.

    \r\n
      \r\n
    • \r\n

      GH-106

      \r\n
    • \r\n
    • \r\n

      GH-107

      \r\n
    • \r\n
    • \r\n

      GH-108

      \r\n
    • \r\n
    • \r\n

      GH-109

      \r\n
    • \r\n
    • \r\n

      GH-112

      \r\n
    • \r\n
    • \r\n

      GH-113

      \r\n
    • \r\n
    • \r\n

      GH-114

      \r\n
    • \r\n
    • \r\n

      GH-115

      \r\n
    • \r\n
    • \r\n

      GH-116

      \r\n
    • \r\n
    • \r\n

      GH-117

      \r\n
    • \r\n
    • \r\n

      GH-118

      \r\n
    • \r\n
    • \r\n

      GH-119

      \r\n
    • \r\n
    • \r\n

      GH-121

      \r\n
    • \r\n
    • \r\n

      Patch by NAITOH Jun.

      \r\n
    • \r\n
    \r\n
  • \r\n
  • \r\n

    Improved parse performance when an attribute has many\r\n<s.

    \r\n
      \r\n
    • GH-124
    • \r\n
    \r\n
  • \r\n
\r\n

Fixes

\r\n
    \r\n
  • \r\n

    XPath: Fixed a bug of normalize_space(array).

    \r\n
      \r\n
    • \r\n

      GH-110

      \r\n
    • \r\n
    • \r\n

      GH-111

      \r\n
    • \r\n
    • \r\n

      Patch by flatisland.

      \r\n
    • \r\n
    \r\n
  • \r\n
  • \r\n

    XPath: Fixed a bug that wrong position is used with nested path.

    \r\n
      \r\n
    • \r\n

      GH-110

      \r\n
    • \r\n
    • \r\n

      GH-122

      \r\n
    • \r\n
    • \r\n

      Reported by jcavalieri.

      \r\n
    • \r\n
    • \r\n

      Patch by NAITOH Jun.

      \r\n
    • \r\n
    \r\n
  • \r\n
  • \r\n

    Fixed a bug that an exception message can't be generated for\r\ninvalid encoding XML.

    \r\n
  • \r\n
\r\n\r\n
\r\n

... (truncated)

\r\n
\r\n
\r\nChangelog\r\n

Sourced from rexml's\r\nchangelog.

\r\n
\r\n

3.2.8 - 2024-05-16 {#version-3-2-8}

\r\n

Fixes

\r\n
    \r\n
  • Suppressed a warning
  • \r\n
\r\n

3.2.7 - 2024-05-16 {#version-3-2-7}

\r\n

Improvements

\r\n
    \r\n
  • \r\n

    Improve parse performance by using StringScanner.

    \r\n
      \r\n
    • \r\n

      GH-106

      \r\n
    • \r\n
    • \r\n

      GH-107

      \r\n
    • \r\n
    • \r\n

      GH-108

      \r\n
    • \r\n
    • \r\n

      GH-109

      \r\n
    • \r\n
    • \r\n

      GH-112

      \r\n
    • \r\n
    • \r\n

      GH-113

      \r\n
    • \r\n
    • \r\n

      GH-114

      \r\n
    • \r\n
    • \r\n

      GH-115

      \r\n
    • \r\n
    • \r\n

      GH-116

      \r\n
    • \r\n
    • \r\n

      GH-117

      \r\n
    • \r\n
    • \r\n

      GH-118

      \r\n
    • \r\n
    • \r\n

      GH-119

      \r\n
    • \r\n
    • \r\n

      GH-121

      \r\n
    • \r\n
    • \r\n

      Patch by NAITOH Jun.

      \r\n
    • \r\n
    \r\n
  • \r\n
  • \r\n

    Improved parse performance when an attribute has many\r\n<s.

    \r\n
      \r\n
    • GH-124
    • \r\n
    \r\n
  • \r\n
\r\n

Fixes

\r\n
    \r\n
  • \r\n

    XPath: Fixed a bug of normalize_space(array).

    \r\n
      \r\n
    • \r\n

      GH-110

      \r\n
    • \r\n
    • \r\n

      GH-111

      \r\n
    • \r\n
    • \r\n

      Patch by flatisland.

      \r\n
    • \r\n
    \r\n
  • \r\n
  • \r\n

    XPath: Fixed a bug that wrong position is used with nested path.

    \r\n
      \r\n
    • \r\n

      GH-110

      \r\n
    • \r\n
    • \r\n

      GH-122

      \r\n
    • \r\n
    • \r\n

      Reported by jcavalieri.

      \r\n
    • \r\n
    • \r\n

      Patch by NAITOH Jun.

      \r\n
    • \r\n
    \r\n
  • \r\n
  • \r\n

    Fixed a bug that an exception message can't be generated for

    \r\n
  • \r\n
\r\n\r\n
\r\n

... (truncated)

\r\n
\r\n
\r\nCommits\r\n
    \r\n
  • 1cf37ba\r\nAdd 3.2.8 entry
  • \r\n
  • b67081c\r\nRemove an unused variable (#128)
  • \r\n
  • 94e180e\r\nSuppress a warning
  • \r\n
  • d574ba5\r\nci: install only gems required for running tests (#129)
  • \r\n
  • 4670f8f\r\nAdd missing Thanks section
  • \r\n
  • 9ba35f9\r\nBump version
  • \r\n
  • 085def0\r\nAdd 3.2.7 entry
  • \r\n
  • 4325835\r\nRead quoted attributes in chunks (#126)
  • \r\n
  • e77365e\r\nExclude older than 2.6 on macos-14
  • \r\n
  • bf2c8ed\r\nMove development dependencies to Gemfile (#124)
  • \r\n
  • Additional commits viewable in compare\r\nview
  • \r\n
\r\n
\r\n
\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=rexml&package-manager=bundler&previous-version=3.2.5&new-version=3.2.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don't\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n
\r\nDependabot commands and options\r\n
\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot show ignore conditions` will show all\r\nof the ignore conditions of the specified dependency\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\nYou can disable automated security fix PRs for this repo from the\r\n[Security Alerts\r\npage](https://github.com/ackama/nzsl-share/network/alerts).\r\n\r\n
\r\n\r\nSigned-off-by: dependabot[bot] \r\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>","shortMessageHtmlLink":"Bump rexml from 3.2.5 to 3.2.8 (#635)"}},{"before":null,"after":"792d6d88d0f2373df29aa437e1f0e71595024a2e","ref":"refs/heads/dependabot/bundler/rexml-3.2.8","pushedAt":"2024-05-16T18:51:03.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"Bump rexml from 3.2.5 to 3.2.8\n\nBumps [rexml](https://github.com/ruby/rexml) from 3.2.5 to 3.2.8.\n- [Release notes](https://github.com/ruby/rexml/releases)\n- [Changelog](https://github.com/ruby/rexml/blob/master/NEWS.md)\n- [Commits](https://github.com/ruby/rexml/compare/v3.2.5...v3.2.8)\n\n---\nupdated-dependencies:\n- dependency-name: rexml\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"Bump rexml from 3.2.5 to 3.2.8"}},{"before":"256a259051c38bab940e55e3b86a866a9a9511bf","after":"e289b9a25b1aa539927c9693621ca30cc50f2075","ref":"refs/heads/production","pushedAt":"2024-05-14T23:36:06.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"Merge pull request #634 from ackama/main\n\nstaging -> production","shortMessageHtmlLink":"Merge pull request #634 from ackama/main"}},{"before":"b30a3ca393b556c22c5b1f4bf6dc8402b845c217","after":null,"ref":"refs/heads/dependabot/bundler/nokogiri-1.16.5","pushedAt":"2024-05-14T23:00:16.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"}},{"before":"b2247fc78c954891342dae9e37d396f476612ac6","after":"51e2b026fa35236c6d1362155c436cea62de9468","ref":"refs/heads/main","pushedAt":"2024-05-14T23:00:15.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"Bump nokogiri from 1.16.2 to 1.16.5 (#633)\n\nBumps [nokogiri](https://github.com/sparklemotion/nokogiri) from 1.16.2\r\nto 1.16.5.\r\n
\r\nRelease notes\r\n

Sourced from nokogiri's\r\nreleases.

\r\n
\r\n

v1.16.5 / 2024-05-13

\r\n

Security

\r\n
    \r\n
  • [CRuby] Vendored libxml2 is updated to address CVE-2024-34459. See\r\nGHSA-r95h-9x8f-r3f7\r\nfor more information.
  • \r\n
\r\n

Dependencies

\r\n
    \r\n
  • [CRuby] Vendored libxml2 is updated to v2.12.7\r\nfrom v2.12.6. (@​flavorjones)
  • \r\n
\r\n
\r\n

sha256 checksums:

\r\n\r\n
af0f44fa3e664dfb2aa10de8b551447d720c1e8d1f0aa3f35783dcc43e40a874\r\nnokogiri-1.16.5-aarch64-linux.gem\r\n23dc2357b26409a5c33b7e32a82902f0e9995305420f16d1a03ab3ea1a482fec\r\nnokogiri-1.16.5-arm-linux.gem\r\n950d037530edb49f75ad35de0b8038b970a7dda57e2b6326895b0e49fadf6214\r\nnokogiri-1.16.5-arm64-darwin.gem\r\nb7aefc94370c62476b8528e8d8abb6160203abd84a1f4eceda8f1aa8974d9989\r\nnokogiri-1.16.5-java.gem\r\nec2167160df8fec3137bf95d574ed80ebc1d002bb3b281546b60b4aa9002466e\r\nnokogiri-1.16.5-x64-mingw-ucrt.gem\r\n6984200491fac69974005ecfa2de129d61843d345eafa5d6f58e8b908d1cf107\r\nnokogiri-1.16.5-x64-mingw32.gem\r\nabdc389ab1ec6604492da16bd9d06ad746fdb6bd6a1bd274c400d61ffcadb3c4\r\nnokogiri-1.16.5-x86-linux.gem\r\n63d24981345856f2baf7f4089870a62d3042fb8d3021b280fb04fc052532e3c4\r\nnokogiri-1.16.5-x86-mingw32.gem\r\n71b5f54e378c433d13df67c3b71acc4716129da62402d8181f310c4216a63279\r\nnokogiri-1.16.5-x86_64-darwin.gem\r\n0ca238da870066bed2f7837af6f35791bb9b76c4c5638999c46aac44818a6a97\r\nnokogiri-1.16.5-x86_64-linux.gem\r\nec36162c68984fa0a90a5c4ae7ab7759460639e716cc1ce75f34c3cb54158ad2\r\nnokogiri-1.16.5.gem\r\n
\r\n

v1.16.4 / 2024-04-10

\r\n

Dependencies

\r\n
    \r\n
  • [CRuby] Vendored zlib in the precompiled native gems is updated to\r\nv1.3.1 from v1.3. Nokogiri\r\nis not affected by the minizip CVE patched in this version, but this\r\nupdate may satisfy some security scanners. Related, see this\r\ndiscussion about removing the compression libraries altogether in a\r\nfuture version of Nokogiri.
  • \r\n
\r\n
\r\n

sha256 checksums:

\r\n\r\n
bdb1dc4378ebcf3ade8f440c7df68f6d76946a1a96c4823a2b4c53c01a320cd5\r\nnokogiri-1.16.4-aarch64-linux.gem\r\n0c994b9996d5576eddcc3201a94ef2bff6fc3627c4ae4d2708b0ec9b9743ec6a\r\nnokogiri-1.16.4-arm-linux.gem\r\n8e86abb64c93c06d3c588042a0e757279e8f1dc88b5210a00be892a9a7a27196\r\nnokogiri-1.16.4-arm64-darwin.gem\r\nbf84fa28be4943692bd64772186e0832fb1061f80714ccb93e111e9d72b1cadc\r\nnokogiri-1.16.4-java.gem\r\na46808467c1f63a2031e1ca0715cd5336bb4ec759e9c0e2f4c951c1cc30994ae\r\nnokogiri-1.16.4-x64-mingw-ucrt.gem\r\n4cdf64bc5e9443ec3e0b595347ecc8affe21968d9ae934c0825d26630ef96468\r\nnokogiri-1.16.4-x64-mingw32.gem\r\nd86d21bae47dd9f6f5223055e45d33fae08b0b89aad94cbc0ece4f4274fa7af5\r\nnokogiri-1.16.4-x86-linux.gem\r\nd488b872884844686780fda7cf5da44ee884d32faa713a55aeb4736d76718168\r\nnokogiri-1.16.4-x86-mingw32.gem\r\na896e52a56951ffb0e6a9279afbf485d683e357a053d27f4cfcb2a73b0824628\r\nnokogiri-1.16.4-x86_64-darwin.gem\r\n92ff4f09910255fec84b3bc4c4b182e94cada3ed12b9f7a6ea058e0af186fb31\r\nnokogiri-1.16.4-x86_64-linux.gem\r\n</tr></table> \r\n
\r\n
\r\n

... (truncated)

\r\n
\r\n
\r\nChangelog\r\n

Sourced from nokogiri's\r\nchangelog.

\r\n
\r\n

v1.16.5

\r\n

Security

\r\n
    \r\n
  • [CRuby] Vendored libxml2 is updated to address CVE-2024-34459. See\r\nGHSA-r95h-9x8f-r3f7\r\nfor more information.
  • \r\n
\r\n

Dependencies

\r\n
    \r\n
  • [CRuby] Vendored libxml2 is updated to v2.12.7\r\nfrom v2.12.6. (@​flavorjones)
  • \r\n
\r\n

v1.16.4 / 2024-04-10

\r\n

Dependencies

\r\n
    \r\n
  • [CRuby] Vendored zlib in the precompiled native gems is updated to\r\nv1.3.1 from v1.3. Nokogiri\r\nis not affected by the minizip CVE patched in this version, but this\r\nupdate may satisfy some security scanners. Related, see this\r\ndiscussion about removing the compression libraries altogether in a\r\nfuture version of Nokogiri.
  • \r\n
\r\n

v1.16.3 / 2024-03-15

\r\n

Dependencies

\r\n
    \r\n
  • [CRuby] Vendored libxml2 is updated to v2.12.6\r\nfrom v2.12.5. (@​flavorjones)
  • \r\n
\r\n

Changed

\r\n
    \r\n
  • [CRuby] XML::Reader sets the @encoding\r\ninstance variable during reading if it is not passed into the\r\ninitializer. Previously, it would remain nil. The behavior\r\nof Reader#encoding has not changed. This works around\r\nchanges to how libxml2 reports the encoding used in v2.12.6.
  • \r\n
\r\n
\r\n
\r\n
\r\nCommits\r\n
    \r\n
  • cd70bd3\r\nversion bump to v1.16.5
  • \r\n
  • afc36de\r\ndep: update vendored libxml2 to v2.12.7 (#3191)
  • \r\n
  • 41b4f08\r\nci: add arm64-darwin coverage using macos-14
  • \r\n
  • 67b9e86\r\ndep: update libxml2 to v2.12.7
  • \r\n
  • 17c0362\r\nversion bump to v1.16.4
  • \r\n
  • 1c329e9\r\ndep: update to zlib 1.3.1 (v1.16.x) (#3175)
  • \r\n
  • edeac07\r\ndep: update to zlib 1.3.1
  • \r\n
  • 80fb608\r\nversion bump to v1.16.3
  • \r\n
  • 710bd96\r\ndep: update libxml 2.12.6 (branch v1.16.x) (#3151)
  • \r\n
  • 461a96e\r\nfix: Reader#read sets @​encoding if it is\r\nunset
  • \r\n
  • Additional commits viewable in compare\r\nview
  • \r\n
\r\n
\r\n
\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=nokogiri&package-manager=bundler&previous-version=1.16.2&new-version=1.16.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don't\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n
\r\nDependabot commands and options\r\n
\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot show ignore conditions` will show all\r\nof the ignore conditions of the specified dependency\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\nYou can disable automated security fix PRs for this repo from the\r\n[Security Alerts\r\npage](https://github.com/ackama/nzsl-share/network/alerts).\r\n\r\n
\r\n\r\nSigned-off-by: dependabot[bot] \r\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>","shortMessageHtmlLink":"Bump nokogiri from 1.16.2 to 1.16.5 (#633)"}},{"before":null,"after":"b30a3ca393b556c22c5b1f4bf6dc8402b845c217","ref":"refs/heads/dependabot/bundler/nokogiri-1.16.5","pushedAt":"2024-05-13T23:38:24.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"Bump nokogiri from 1.16.2 to 1.16.5\n\nBumps [nokogiri](https://github.com/sparklemotion/nokogiri) from 1.16.2 to 1.16.5.\n- [Release notes](https://github.com/sparklemotion/nokogiri/releases)\n- [Changelog](https://github.com/sparklemotion/nokogiri/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/sparklemotion/nokogiri/compare/v1.16.2...v1.16.5)\n\n---\nupdated-dependencies:\n- dependency-name: nokogiri\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"Bump nokogiri from 1.16.2 to 1.16.5"}},{"before":"ac1d9acceca1e7f1a4306fe2316f418fab6f95fb","after":"256a259051c38bab940e55e3b86a866a9a9511bf","ref":"refs/heads/production","pushedAt":"2024-04-29T19:13:43.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"nzlaura","name":"Laura Corkin","path":"/nzlaura","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/57056459?s=80&v=4"},"commit":{"message":"Merge pull request #632 from ackama/main\n\nstaging -> production","shortMessageHtmlLink":"Merge pull request #632 from ackama/main"}},{"before":"993d4bdffbdb39f8aa559100517f439a49443a28","after":"b2247fc78c954891342dae9e37d396f476612ac6","ref":"refs/heads/main","pushedAt":"2024-04-29T03:37:31.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"nzlaura","name":"Laura Corkin","path":"/nzlaura","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/57056459?s=80&v=4"},"commit":{"message":"Upgrade Ruby from 3.1.4 -> 3.1.5 to address cve-2024-27282 (#631)\n\nhttps://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/","shortMessageHtmlLink":"Upgrade Ruby from 3.1.4 -> 3.1.5 to address cve-2024-27282 (#631)"}},{"before":"6a300569417dbb99f6953dd046f6443ac8d928da","after":null,"ref":"refs/heads/nzlaura-patch-1","pushedAt":"2024-04-29T03:37:31.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"nzlaura","name":"Laura Corkin","path":"/nzlaura","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/57056459?s=80&v=4"}},{"before":"cc7f0ef3615151b21690ff6ee2d4a7c975cf4dc4","after":"6a300569417dbb99f6953dd046f6443ac8d928da","ref":"refs/heads/nzlaura-patch-1","pushedAt":"2024-04-29T03:17:53.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"nzlaura","name":"Laura Corkin","path":"/nzlaura","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/57056459?s=80&v=4"},"commit":{"message":"Update Gemfile.lock","shortMessageHtmlLink":"Update Gemfile.lock"}},{"before":null,"after":"cc7f0ef3615151b21690ff6ee2d4a7c975cf4dc4","ref":"refs/heads/nzlaura-patch-1","pushedAt":"2024-04-29T03:16:50.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"nzlaura","name":"Laura Corkin","path":"/nzlaura","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/57056459?s=80&v=4"},"commit":{"message":"Update .ruby-version","shortMessageHtmlLink":"Update .ruby-version"}},{"before":"b71e4ebe9159fdb44a1d373a6f1baf174776d4de","after":"ac1d9acceca1e7f1a4306fe2316f418fab6f95fb","ref":"refs/heads/production","pushedAt":"2024-04-16T04:26:10.000Z","pushType":"pr_merge","commitsCount":7,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"Merge pull request #626 from ackama/main\n\nstaging -> production","shortMessageHtmlLink":"Merge pull request #626 from ackama/main"}},{"before":"5e19753103ae3d68aa111963b7a0c9fe7bece135","after":null,"ref":"refs/heads/dependabot/npm_and_yarn/tar-6.2.1","pushedAt":"2024-04-14T19:07:49.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"}},{"before":"a72142edf77a85a415e17e84e6a17edc5dac6d2f","after":"993d4bdffbdb39f8aa559100517f439a49443a28","ref":"refs/heads/main","pushedAt":"2024-04-14T19:07:49.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"G-Rath","name":"Gareth Jones","path":"/G-Rath","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/3151613?s=80&v=4"},"commit":{"message":"Bump tar from 6.1.13 to 6.2.1 (#630)\n\nBumps [tar](https://github.com/isaacs/node-tar) from 6.1.13 to 6.2.1.\r\n
\r\nChangelog\r\n

Sourced from tar's\r\nchangelog.

\r\n
\r\n

Changelog

\r\n

7.0

\r\n
    \r\n
  • Rewrite in TypeScript, provide ESM and CommonJS hybrid\r\ninterface
  • \r\n
  • Add tree-shake friendly exports, like\r\nimport('tar/create')\r\nand import('tar/read-entry') to get individual functions or\r\nclasses.
  • \r\n
  • Add chmod option that defaults to false, and deprecate\r\nnoChmod. That is, reverse the default option regarding\r\nexplicitly setting file system modes to match tar entry\r\nsettings.
  • \r\n
  • Add processUmask option to avoid having to call\r\nprocess.umask() when chmod: true (or\r\nnoChmod: false) is\r\nset.
  • \r\n
\r\n

6.2

\r\n
    \r\n
  • Add support for brotli compression
  • \r\n
  • Add maxDepth option to prevent extraction into\r\nexcessively\r\ndeep folders.
  • \r\n
\r\n

6.1

\r\n
    \r\n
  • remove dead link to benchmarks (#313)\r\n(@​yetzt)
  • \r\n
  • add examples/explanation of using tar.t (@​isaacs)
  • \r\n
  • ensure close event is emited after stream has ended (@​webark)
  • \r\n
  • replace deprecated String.prototype.substr() (@​CommanderRoot,\r\n@​lukekarrys)
  • \r\n
\r\n

6.0

\r\n
    \r\n
  • Drop support for node 6 and 8
  • \r\n
  • fix symlinks and hardlinks on windows being packed with\r\n\\-style path targets
  • \r\n
\r\n

5.0

\r\n
    \r\n
  • Address unpack race conditions using path reservations
  • \r\n
  • Change large-numbers errors from TypeError to Error
  • \r\n
  • Add TAR_* error codes
  • \r\n
  • Raise TAR_BAD_ARCHIVE warning/error when there are no\r\nvalid\r\nentries found in an archive
  • \r\n
  • do not treat ignored entries as an invalid archive
  • \r\n
  • drop support for node v4
  • \r\n
  • unpack: conditionally use a file mapping to write files on\r\nWindows
  • \r\n
  • Set more portable 'mode' value in portable mode
  • \r\n
  • Set portable gzip option in portable mode
  • \r\n
\r\n\r\n
\r\n

... (truncated)

\r\n
\r\n
\r\nCommits\r\n
    \r\n
  • bef7b1e\r\n6.2.1
  • \r\n
  • fe8cd57\r\nprevent extraction in excessively deep subfolders
  • \r\n
  • fe7ebfd\r\nremove security.md
  • \r\n
  • 5bc9d40\r\n6.2.0
  • \r\n
  • fe1ef5e\r\nchangelog 6.2
  • \r\n
  • e483220\r\nget rid of npm lint stuff
  • \r\n
  • 689928a\r\nci that works outside of npm org
  • \r\n
  • db6f539\r\nfile inference improvements for .tbr and .tgz
  • \r\n
  • 336fa8f\r\nrefactor: dry and other pr comments
  • \r\n
  • eeba222\r\nchore: lint fixes
  • \r\n
  • Additional commits viewable in compare\r\nview
  • \r\n
\r\n
\r\n
\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tar&package-manager=npm_and_yarn&previous-version=6.1.13&new-version=6.2.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don't\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n
\r\nDependabot commands and options\r\n
\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot show ignore conditions` will show all\r\nof the ignore conditions of the specified dependency\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\nYou can disable automated security fix PRs for this repo from the\r\n[Security Alerts\r\npage](https://github.com/ackama/nzsl-share/network/alerts).\r\n\r\n
\r\n\r\nSigned-off-by: dependabot[bot] \r\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>","shortMessageHtmlLink":"Bump tar from 6.1.13 to 6.2.1 (#630)"}}],"hasNextPage":true,"hasPreviousPage":false,"activityType":"all","actor":null,"timePeriod":"all","sort":"DESC","perPage":30,"cursor":"djE6ks8AAAAEgVIKZwA","startCursor":null,"endCursor":null}},"title":"Activity · ackama/nzsl-share"}