DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-6ppp-fx25-74mg

Package

gitlab-rails-ce-fips-19.3

Component

nokogiri

Latest update

Pending upstream fix

Aliases

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://github.com/advisories/GHSA-p67v-3w7g-wjg7

Updates

Status

Pending upstream fix

Impact

nokogiri 1.19.3 is updated to 1.19.4 in the non-FIPS gitlab-rails-ce-19.3 package. In the FIPS build, adding nokogiri to the bundle update --conservative step rewrites the platform-specific Gemfile.lock entries and breaks the FIPS-only 'Reinstall gRPC gem' step (the system bundler re-resolution dead-ends on solargraph -> bundler ~> 2.0). Resolution requires upstream GitLab to ship a Gemfile.lock with nokogiri >= 1.19.4.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.