From 32de509d215e91f0150db9005bddf0bfd7be376b Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 18 May 2021 19:15:09 +0000 Subject: [PATCH] fix: Gemfile & Gemfile.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1293239 --- Gemfile | 2 +- Gemfile.lock | 14 +++++++++----- 2 files changed, 10 insertions(+), 6 deletions(-) diff --git a/Gemfile b/Gemfile index 25efdd9..594cec1 100644 --- a/Gemfile +++ b/Gemfile @@ -1,7 +1,7 @@ source 'https://rubygems.org' gem 'httparty' -gem 'nokogiri', '>= 1.10.8' +gem 'nokogiri', '>= 1.11.4' gem 'model_un' gem 'aws-sdk', '>= 1.52.0' gem 'timecop' diff --git a/Gemfile.lock b/Gemfile.lock index 6726a43..8606bf3 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -825,14 +825,16 @@ GEM rb-inotify (>= 0.9) lumberjack (1.0.9) method_source (0.8.2) - mini_portile2 (2.4.0) + mini_portile2 (2.5.1) minitest (5.4.0) model_un (0.2.1) multi_json (1.10.1) multi_xml (0.5.5) - nokogiri (1.10.8) - mini_portile2 (~> 2.4.0) - nokogiri (1.10.8-java) + nokogiri (1.11.4) + mini_portile2 (~> 2.5.0) + racc (~> 1.4) + nokogiri (1.11.4-java) + racc (~> 1.4) pry (0.10.1) coderay (~> 1.1.0) method_source (~> 0.8.1) @@ -845,6 +847,8 @@ GEM pry-byebug (1.3.3) byebug (~> 2.7) pry (~> 0.10) + racc (1.5.2) + racc (1.5.2-java) rack (1.5.2) rack-protection (1.5.3) rack @@ -907,7 +911,7 @@ DEPENDENCIES guard-rspec httparty model_un - nokogiri (>= 1.10.8) + nokogiri (>= 1.11.4) pry pry-byebug rack-test