-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Fix for 74 vulnerabilities #42
base: master
Are you sure you want to change the base?
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-1290051 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-1290052 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-2400638 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-3237231 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-3237232 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-569599 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-569600 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-2803851 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-560837 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-569156 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-569601 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-632514 - https://snyk.io/vuln/SNYK-RUBY-ACTIVEJOB-72640 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-1080913 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-2960802 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-3237239 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-3237242 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-3360028 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-569598 - https://snyk.io/vuln/SNYK-RUBY-ADDRESSABLE-1316242 - https://snyk.io/vuln/SNYK-RUBY-BETTERERRORS-1583446 - https://snyk.io/vuln/SNYK-RUBY-CARRIERWAVE-1070797 - https://snyk.io/vuln/SNYK-RUBY-CARRIERWAVE-1070798 - https://snyk.io/vuln/SNYK-RUBY-CARRIERWAVE-20417 - https://snyk.io/vuln/SNYK-RUBY-GLOBALID-3237234 - https://snyk.io/vuln/SNYK-RUBY-JQUERYRAILS-450225 - https://snyk.io/vuln/SNYK-RUBY-JQUERYRAILS-565439 - https://snyk.io/vuln/SNYK-RUBY-JSON-560838 - https://snyk.io/vuln/SNYK-RUBY-KAMINARI-570586 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-3168317 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-3168318 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-3168649 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1055008 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1293239 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1726792 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2413994 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2620374 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2630623 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2630898 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2840634 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-3052880 - https://snyk.io/vuln/SNYK-RUBY-OAUTH-1012727 - https://snyk.io/vuln/SNYK-RUBY-PUMA-1291014 - https://snyk.io/vuln/SNYK-RUBY-PUMA-1730572 - https://snyk.io/vuln/SNYK-RUBY-PUMA-2400629 - https://snyk.io/vuln/SNYK-RUBY-PUMA-2437090 - https://snyk.io/vuln/SNYK-RUBY-PUMA-570205 - https://snyk.io/vuln/SNYK-RUBY-PUMA-570206 - https://snyk.io/vuln/SNYK-RUBY-RACK-1061917 - https://snyk.io/vuln/SNYK-RUBY-RACK-2848599 - https://snyk.io/vuln/SNYK-RUBY-RACK-2848600 - https://snyk.io/vuln/SNYK-RUBY-RACK-3237240 - https://snyk.io/vuln/SNYK-RUBY-RACK-3356639 - https://snyk.io/vuln/SNYK-RUBY-RACK-569066 - https://snyk.io/vuln/SNYK-RUBY-RACK-572377 - https://snyk.io/vuln/SNYK-RUBY-RACKPROTECTION-20394 - https://snyk.io/vuln/SNYK-RUBY-RAILS-1071903 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-2935879 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168316 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168646 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168647 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168648 - https://snyk.io/vuln/SNYK-RUBY-RAILTIES-20454 - https://snyk.io/vuln/SNYK-RUBY-RDOC-1279617 - https://snyk.io/vuln/SNYK-RUBY-RDOC-1316279 - https://snyk.io/vuln/SNYK-RUBY-REDCARPET-1059089 - https://snyk.io/vuln/SNYK-RUBY-SIDEKIQ-1090607 - https://snyk.io/vuln/SNYK-RUBY-SIDEKIQ-1729733 - https://snyk.io/vuln/SNYK-RUBY-SIDEKIQ-2359050 - https://snyk.io/vuln/SNYK-RUBY-SINATRA-20488 - https://snyk.io/vuln/SNYK-RUBY-SINATRA-22027 - https://snyk.io/vuln/SNYK-RUBY-SINATRA-2806372 - https://snyk.io/vuln/SNYK-RUBY-SINATRA-3150405 - https://snyk.io/vuln/SNYK-RUBY-TZINFO-2958048
gem 'vcr', '~> 3.0' | ||
end | ||
|
||
group :production do | ||
gem 'bonsai-elasticsearch-rails', '~> 0.0.4' | ||
gem 'fog', '~> 1.36' | ||
gem 'fog', '~> 1.42', '>= 1.42.0' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Style/StringLiterals: Prefer double-quoted strings unless you need single quotes to avoid extra backslashes for escaping.
gem 'shoulda-matchers', '~> 3.1' | ||
gem 'webmock', '~> 2.1' | ||
gem 'shoulda-matchers', '~> 3.1', '>= 3.1.2' | ||
gem 'webmock', '~> 2.3', '>= 2.3.2' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Style/StringLiterals: Prefer double-quoted strings unless you need single quotes to avoid extra backslashes for escaping.
gem 'guard-rspec', '~> 4.7' | ||
gem 'shoulda-matchers', '~> 3.1' | ||
gem 'webmock', '~> 2.1' | ||
gem 'shoulda-matchers', '~> 3.1', '>= 3.1.2' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Style/StringLiterals: Prefer double-quoted strings unless you need single quotes to avoid extra backslashes for escaping.
gem 'codeclimate-test-reporter', '~> 0.6.0', require: nil | ||
gem 'database_cleaner', '~> 1.5' | ||
gem 'factory_girl_rails', '~> 4.7' | ||
gem 'factory_girl_rails', '~> 4.9', '>= 4.9.0' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Style/StringLiterals: Prefer double-quoted strings unless you need single quotes to avoid extra backslashes for escaping.
gem 'capybara-webkit', '~> 1.15' | ||
gem 'capybara', '~> 3.31', '>= 3.31.0' | ||
gem 'capybara-screenshot', '~> 1.0', '>= 1.0.24' | ||
gem 'capybara-webkit', '~> 1.15', '>= 1.15.1' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Style/StringLiterals: Prefer double-quoted strings unless you need single quotes to avoid extra backslashes for escaping.
gem 'sinatra', '~> 1.4.7' # for Sidekiq monitoring https://github.com/mperham/sidekiq/wiki/Monitoring | ||
gem 'rails-footnotes', '~> 4.1' | ||
gem 'rails_best_practices', '~> 1.17' | ||
gem 'sinatra', '~> 2.2.3' # for Sidekiq monitoring https://github.com/mperham/sidekiq/wiki/Monitoring |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Style/StringLiterals: Prefer double-quoted strings unless you need single quotes to avoid extra backslashes for escaping.
gem 'memory_profiler', '~> 0.9.6' | ||
gem 'meta_request', '~> 0.4.0' | ||
gem 'meta_request', '~> 0.7.0' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Style/StringLiterals: Prefer double-quoted strings unless you need single quotes to avoid extra backslashes for escaping.
gem 'immigrant', '~> 0.3.5' | ||
gem 'letter_opener', '~> 1.4' | ||
gem 'immigrant', '~> 0.3.6' | ||
gem 'letter_opener', '~> 1.6', '>= 1.6.0' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Style/StringLiterals: Prefer double-quoted strings unless you need single quotes to avoid extra backslashes for escaping.
gem 'gem_bench', require: false | ||
gem 'immigrant', '~> 0.3.5' | ||
gem 'letter_opener', '~> 1.4' | ||
gem 'immigrant', '~> 0.3.6' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Style/StringLiterals: Prefer double-quoted strings unless you need single quotes to avoid extra backslashes for escaping.
gem 'bullet', '~> 5.3' | ||
gem 'derailed_benchmarks', '~> 1.3' | ||
gem 'bullet', '~> 5.7', '>= 5.7.5' | ||
gem 'derailed_benchmarks', '~> 1.3', '>= 1.3.4' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Style/StringLiterals: Prefer double-quoted strings unless you need single quotes to avoid extra backslashes for escaping.
Snyk has created this PR to fix one or more vulnerable packages in the `rubygems` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-RUBY-ACTIONPACK-1290051
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-ACTIONPACK-1290052
Why? Has a fix available, CVSS 7.4
SNYK-RUBY-ACTIONPACK-2400638
Why? Has a fix available, CVSS 5.3
SNYK-RUBY-ACTIONPACK-3237231
Why? Has a fix available, CVSS 5.3
SNYK-RUBY-ACTIONPACK-3237232
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
SNYK-RUBY-ACTIONPACK-569599
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
SNYK-RUBY-ACTIONPACK-569600
Why? Proof of Concept exploit, Has a fix available, CVSS 5.4
SNYK-RUBY-ACTIONVIEW-2803851
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
SNYK-RUBY-ACTIONVIEW-560837
Why? Mature exploit, Has a fix available, CVSS 9.8
SNYK-RUBY-ACTIONVIEW-569156
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-RUBY-ACTIONVIEW-569601
Why? Has a fix available, CVSS 4.7
SNYK-RUBY-ACTIONVIEW-632514
Why? Has a fix available, CVSS 5.3
SNYK-RUBY-ACTIVEJOB-72640
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-ACTIVERECORD-1080913
Why? Has a fix available, CVSS 9.8
SNYK-RUBY-ACTIVERECORD-2960802
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-ACTIVERECORD-3237239
Why? Has a fix available, CVSS 5.3
SNYK-RUBY-ACTIVESUPPORT-3237242
Why? Recently disclosed, Has a fix available, CVSS 6.1
SNYK-RUBY-ACTIVESUPPORT-3360028
Why? Mature exploit, Has a fix available, CVSS 8.1
SNYK-RUBY-ACTIVESUPPORT-569598
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-ADDRESSABLE-1316242
Why? Has a fix available, CVSS 6.3
SNYK-RUBY-BETTERERRORS-1583446
Why? Has a fix available, CVSS 4.3
SNYK-RUBY-CARRIERWAVE-1070797
Why? Has a fix available, CVSS 5.9
SNYK-RUBY-CARRIERWAVE-1070798
Why? Has a fix available, CVSS 5.3
SNYK-RUBY-CARRIERWAVE-20417
Why? Has a fix available, CVSS 5.3
SNYK-RUBY-GLOBALID-3237234
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
SNYK-RUBY-JQUERYRAILS-450225
Why? Mature exploit, Has a fix available, CVSS 6.3
SNYK-RUBY-JQUERYRAILS-565439
Why? Has a fix available, CVSS 9.3
SNYK-RUBY-JSON-560838
Why? Proof of Concept exploit, Has a fix available, CVSS 6.4
SNYK-RUBY-KAMINARI-570586
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-LOOFAH-3168317
Why? Has a fix available, CVSS 6.1
SNYK-RUBY-LOOFAH-3168318
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-LOOFAH-3168649
Why? Has a fix available, CVSS 2.6
SNYK-RUBY-NOKOGIRI-1055008
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-RUBY-NOKOGIRI-1293239
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-NOKOGIRI-1726792
Why? Has a fix available, CVSS 8.1
SNYK-RUBY-NOKOGIRI-2413994
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-NOKOGIRI-2620374
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-NOKOGIRI-2630623
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-NOKOGIRI-2630898
Why? Has a fix available, CVSS 8.2
SNYK-RUBY-NOKOGIRI-2840634
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-NOKOGIRI-3052880
Why? Has a fix available, CVSS 7.4
SNYK-RUBY-OAUTH-1012727
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-PUMA-1291014
Why? Has a fix available, CVSS 3.7
SNYK-RUBY-PUMA-1730572
Why? Has a fix available, CVSS 8
SNYK-RUBY-PUMA-2400629
Why? Has a fix available, CVSS 9.1
SNYK-RUBY-PUMA-2437090
Why? Has a fix available, CVSS 6.5
SNYK-RUBY-PUMA-570205
Why? Has a fix available, CVSS 6.5
SNYK-RUBY-PUMA-570206
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
SNYK-RUBY-RACK-1061917
Why? Has a fix available, CVSS 9.8
SNYK-RUBY-RACK-2848599
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-RACK-2848600
Why? Has a fix available, CVSS 5.3
SNYK-RUBY-RACK-3237240
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-RACK-3356639
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-RACK-569066
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
SNYK-RUBY-RACK-572377
Why? Has a fix available, CVSS 3.7
SNYK-RUBY-RACKPROTECTION-20394
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-RUBY-RAILS-1071903
Why? Proof of Concept exploit, Has a fix available, CVSS 4.2
SNYK-RUBY-RAILSHTMLSANITIZER-2935879
Why? Has a fix available, CVSS 5.4
SNYK-RUBY-RAILSHTMLSANITIZER-3168316
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-RAILSHTMLSANITIZER-3168646
Why? Proof of Concept exploit, Has a fix available, CVSS 6.1
SNYK-RUBY-RAILSHTMLSANITIZER-3168647
Why? Has a fix available, CVSS 4.2
SNYK-RUBY-RAILSHTMLSANITIZER-3168648
Why? Has a fix available, CVSS 5.3
SNYK-RUBY-RAILTIES-20454
Why? Has a fix available, CVSS 8.1
SNYK-RUBY-RDOC-1279617
Why? Has a fix available, CVSS 7
SNYK-RUBY-RDOC-1316279
Why? Has a fix available, CVSS 8.3
SNYK-RUBY-REDCARPET-1059089
Why? Proof of Concept exploit, Has a fix available, CVSS 5.4
SNYK-RUBY-SIDEKIQ-1090607
Why? Proof of Concept exploit, Has a fix available, CVSS 5.4
SNYK-RUBY-SIDEKIQ-1729733
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-RUBY-SIDEKIQ-2359050
Why? Has a fix available, CVSS 5.9
SNYK-RUBY-SINATRA-20488
Why? Has a fix available, CVSS 6.1
SNYK-RUBY-SINATRA-22027
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-SINATRA-2806372
Why? Has a fix available, CVSS 8.8
SNYK-RUBY-SINATRA-3150405
Why? Has a fix available, CVSS 7.5
SNYK-RUBY-TZINFO-2958048
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Denial of Service (DoS)
🦉 Cross-site Request Forgery (CSRF)
🦉 Cross-site Scripting (XSS)
🦉 More lessons are available in Snyk Learn