Skip to content

Resolve Dependabot alerts in Jekyll dependencies - #4

Open
SimonPickup wants to merge 1 commit into
masterfrom
security/dependabot-2026-08-05
Open

Resolve Dependabot alerts in Jekyll dependencies#4
SimonPickup wants to merge 1 commit into
masterfrom
security/dependabot-2026-08-05

Conversation

@SimonPickup

Copy link
Copy Markdown
Member

Summary

  • raise the explicit rexml floor to 3.3.9 and lock 3.4.4
  • raise the explicit webrick floor to 1.8.2 and lock 1.9.2
  • retain secure floors in Gemfile so a future lockfile refresh cannot regress below patched versions

This resolves all eight current Dependabot alerts in the repository (two high and six moderate).

Verification

  • bundle check passes with Ruby 3.1.4 / Bundler 2.3.26
  • bundle exec jekyll build --trace completes successfully

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant