nokogiri <1.12.5 has a vulnerability classified as high-risk: CVE-2021-41098. However, this package is currently bundling nokogiri v1.11.0.rc2. That version 1.11.0.rc2 was released in April-2020 and appears to be in-use ONLY to maintain support for ruby v2.3 & 2.4.
Both versions of ruby have been EOL'd for more than a year (https://endoflife.date/ruby):
- ruby 2.3 EOL 3/2019
- ruby 2.4 EOL 3/2020
- Even ruby 2.5 was EOL'd, in 3/2021
To remediate:
Could this module be updated to deprecate support for ruby <2.6 & require the secure nokogiri version?