From 85fc1b7d36299ca77961a04d2380df785d353e31 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 25 May 2020 20:15:44 -0400 Subject: [PATCH] fix: Gemfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-569599 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-569600 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-569601 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-569598 - https://snyk.io/vuln/SNYK-RUBY-PUMA-570205 - https://snyk.io/vuln/SNYK-RUBY-PUMA-570206 --- Gemfile | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/Gemfile b/Gemfile index 925e56f4..c699f846 100644 --- a/Gemfile +++ b/Gemfile @@ -1,34 +1,34 @@ source 'https://rubygems.org' ruby '2.3.5' -gem 'devise', '~> 3.0' +gem 'devise', '~> 4.4', '>= 4.4.2' gem 'geokit', '~> 1.0' gem 'haml', '~> 5.0' gem 'http_accept_language', '~> 2.0' gem 'local_time', '~> 2.0' gem 'obscenity', '~> 1.0', '>= 1.0.2' gem 'pg' -gem 'rails', '~> 4.2.4' -gem 'rails_admin', '~> 1.0' +gem 'rails', '~> 5.2.4', '>= 5.2.4.3' +gem 'rails_admin', '~> 1.2', '>= 1.2.0' gem 'validates_formatting_of', '~> 0.9.0' -gem 'paranoia', '~> 2.2' +gem 'paranoia', '~> 2.4', '>= 2.4.1' gem 'tzinfo-data', platforms: %i[mingw mswin x64_mingw] gem 'byebug', groups: %i[development test] -gem 'dotenv-rails', groups: %i[development test] +gem 'dotenv-rails', '>= 2.2.2', groups: %i[development test] group :assets do - gem 'sass-rails', '>= 4.0.3' + gem 'sass-rails', '>= 5.0.6' gem 'uglifier' end group :development do - gem 'spring' + gem 'spring', '>= 2.0.2' end group :production do - gem 'puma' + gem 'puma', '>= 3.12.6' gem 'rails_12factor' end