From 66609f06fd0334643be8b9e643cb5a668d468c11 Mon Sep 17 00:00:00 2001 From: Sony Mathew Date: Mon, 22 Jun 2026 13:37:58 +0530 Subject: [PATCH] fix: Bump Nokogiri to 1.19.4 (#14807) # Pull Request Template ## Description This updates Nokogiri from `1.19.3` to `1.19.4` so the bundle-audit lint step stops flagging the newly published Nokogiri advisories. Chatwoot's direct Nokogiri usage appears limited to ordinary HTML/XML parsing and selector traversal, but the locked dependency is below the patched floor, so the safe remediation is the patch-level upgrade rather than an advisory override. Fixes [CW-7397](https://linear.app/chatwoot/issue/CW-7397/upgrade-nokogiri-to-1194-for-bundle-audit-advisories) ## Type of change - [x] Bug fix (non-breaking change which fixes an issue) ## How Has This Been Tested? Reference failed build in CI because of bundle audit: https://app.circleci.com/pipelines/github/chatwoot/chatwoot/114392/workflows/8a252bf9-5e58-45fd-af18-a32dbebe978b/jobs/160423 - `bundle exec bundle audit update && bundle exec bundle audit check -v` passed with no vulnerabilities found. - `bundle exec rspec spec/services/website_branding_service_spec.rb spec/presenters/html_parser_spec.rb spec/enterprise/services/enterprise/website_branding_service_spec.rb spec/enterprise/services/captain/tools/simple_page_crawl_service_spec.rb` passed with 27 examples and 0 failures. - `bundle exec rubocop app/services/website_branding_service.rb app/presenters/html_parser.rb enterprise/app/services/page_crawler_service.rb enterprise/app/services/captain/tools/html_page_parser.rb enterprise/app/services/captain/tools/simple_page_crawl_service.rb` passed with no offenses. - `git diff --check` passed. Note: broad `bundle exec rubocop --parallel` still reports existing generated DB/schema offenses unrelated to this lockfile-only dependency bump. ## Checklist: - [x] My code follows the style guidelines of this project - [x] I have performed a self-review of my code - [ ] I have commented on my code, particularly in hard-to-understand areas - [ ] I have made corresponding changes to the documentation - [x] My changes generate no new warnings - [ ] I have added tests that prove my fix is effective or that my feature works - [x] New and existing unit tests pass locally with my changes - [ ] Any dependent changes have been merged and published in downstream modules --- Gemfile.lock | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index 8d6132849..a21f01ab3 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -598,14 +598,14 @@ GEM newrelic_rpm (9.6.0) base64 nio4r (2.7.5) - nokogiri (1.19.3) + nokogiri (1.19.4) mini_portile2 (~> 2.8.2) racc (~> 1.4) - nokogiri (1.19.3-arm64-darwin) + nokogiri (1.19.4-arm64-darwin) racc (~> 1.4) - nokogiri (1.19.3-x86_64-darwin) + nokogiri (1.19.4-x86_64-darwin) racc (~> 1.4) - nokogiri (1.19.3-x86_64-linux-gnu) + nokogiri (1.19.4-x86_64-linux-gnu) racc (~> 1.4) oauth (1.1.6) auth-sanitizer (~> 0.2, >= 0.2.1)