From 39468e92d42c1ff2211763f9bfdc713e670f3334 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 4 Apr 2023 14:18:51 +0000 Subject: [PATCH] fix: Gemfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-1290051 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-1290052 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20255 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20256 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20258 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20264 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-2400638 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-3237231 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-3237232 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-569599 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-569600 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-20262 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-20271 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-2803851 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-560837 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-569156 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-569601 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-632514 - https://snyk.io/vuln/SNYK-RUBY-ACTIVEJOB-72640 - https://snyk.io/vuln/SNYK-RUBY-ACTIVEMODEL-20260 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-1080913 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-20259 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-20270 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-2960802 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-3237239 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-3237242 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-3360028 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-569598 - https://snyk.io/vuln/SNYK-RUBY-ADDRESSABLE-1316242 - https://snyk.io/vuln/SNYK-RUBY-BETTERERRORS-1583446 - https://snyk.io/vuln/SNYK-RUBY-BOOTSTRAPSASS-174549 - https://snyk.io/vuln/SNYK-RUBY-BOOTSTRAPSASS-450237 - https://snyk.io/vuln/SNYK-RUBY-BOOTSTRAPSASS-450238 - https://snyk.io/vuln/SNYK-RUBY-BOOTSTRAPSASS-450239 - https://snyk.io/vuln/SNYK-RUBY-CARRIERWAVE-1070797 - https://snyk.io/vuln/SNYK-RUBY-CARRIERWAVE-1070798 - https://snyk.io/vuln/SNYK-RUBY-CARRIERWAVE-20417 - https://snyk.io/vuln/SNYK-RUBY-CUCUMBER-20442 - https://snyk.io/vuln/SNYK-RUBY-DEVISE-173787 - https://snyk.io/vuln/SNYK-RUBY-DEVISE-20252 - https://snyk.io/vuln/SNYK-RUBY-DEVISE-465098 - https://snyk.io/vuln/SNYK-RUBY-FFI-22037 - https://snyk.io/vuln/SNYK-RUBY-GLOBALID-3237234 - https://snyk.io/vuln/SNYK-RUBY-JQUERYRAILS-20225 - https://snyk.io/vuln/SNYK-RUBY-JQUERYRAILS-450225 - https://snyk.io/vuln/SNYK-RUBY-JQUERYRAILS-565439 - https://snyk.io/vuln/SNYK-RUBY-JQUERYRAILS-575390 - https://snyk.io/vuln/SNYK-RUBY-JQUERYUIRAILS-449592 - https://snyk.io/vuln/SNYK-RUBY-JSON-560838 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-22023 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-3168317 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-474102 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-72548 - https://snyk.io/vuln/SNYK-RUBY-MINIMAGICK-451567 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1055008 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1293239 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1583442 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1726792 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20299 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20367 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20368 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20432 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-22013 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-22014 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2413994 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2620374 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2630623 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2630898 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2840634 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-3052880 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-3357692 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-3357693 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-459107 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-534637 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-552159 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-72433 - https://snyk.io/vuln/SNYK-RUBY-RACK-1061917 - https://snyk.io/vuln/SNYK-RUBY-RACK-2848599 - https://snyk.io/vuln/SNYK-RUBY-RACK-2848600 - https://snyk.io/vuln/SNYK-RUBY-RACK-3237240 - https://snyk.io/vuln/SNYK-RUBY-RACK-3356639 - https://snyk.io/vuln/SNYK-RUBY-RACK-538324 - https://snyk.io/vuln/SNYK-RUBY-RACK-569066 - https://snyk.io/vuln/SNYK-RUBY-RACK-572377 - https://snyk.io/vuln/SNYK-RUBY-RACK-72567 - https://snyk.io/vuln/SNYK-RUBY-RAILS-1071903 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-22025 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-2935879 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168316 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168646 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168647 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168648 - https://snyk.io/vuln/SNYK-RUBY-RAILTIES-20454 - https://snyk.io/vuln/SNYK-RUBY-RAKE-552000 - https://snyk.io/vuln/SNYK-RUBY-RDOC-1279617 - https://snyk.io/vuln/SNYK-RUBY-RDOC-1316279 - https://snyk.io/vuln/SNYK-RUBY-RUBYZIP-20336 - https://snyk.io/vuln/SNYK-RUBY-RUBYZIP-22039 - https://snyk.io/vuln/SNYK-RUBY-RUBYZIP-469156 - https://snyk.io/vuln/SNYK-RUBY-SIMPLEFORM-469443 - https://snyk.io/vuln/SNYK-RUBY-SPROCKETS-22032 - https://snyk.io/vuln/SNYK-RUBY-TURBOLINKS-20429 - https://snyk.io/vuln/SNYK-RUBY-TZINFO-2958048 - https://snyk.io/vuln/SNYK-RUBY-UGLIFIER-20236 --- Gemfile | 34 +++++++++++++++++----------------- 1 file changed, 17 insertions(+), 17 deletions(-) diff --git a/Gemfile b/Gemfile index 998e45e..700dc45 100644 --- a/Gemfile +++ b/Gemfile @@ -1,20 +1,20 @@ source 'https://rubygems.org' ruby '2.1.2' -gem 'rails', '4.2.5' -gem 'sass-rails', '~> 4.0.3' -gem 'uglifier', '>= 1.3.0' -gem 'coffee-rails', '~> 4.0.0' -gem 'jquery-rails' -gem 'turbolinks' -gem 'jbuilder', '~> 2.0' -gem 'sdoc', '~> 0.4.0', group: :doc +gem 'rails', '6.1.7.3' +gem 'sass-rails', '~> 6.0.0' +gem 'uglifier', '>= 2.7.2' +gem 'coffee-rails', '~> 4.2.2' +gem 'jquery-rails', '>= 4.4.0' +gem 'turbolinks', '>= 5.0.0' +gem 'jbuilder', '~> 2.6', '>= 2.6.4' +gem 'sdoc', '~> 1.0.0', group: :doc gem 'spring', group: :development -gem 'bootstrap-sass' -gem 'devise' +gem 'bootstrap-sass', '>= 3.4.0' +gem 'devise', '>= 4.7.1' gem 'pundit' -gem 'simple_form' -gem 'slim-rails' +gem 'simple_form', '>= 5.0.0' +gem 'slim-rails', '>= 3.1.0' gem 'bootstrap3_autocomplete_input' gem 'twitter-typeahead-rails' @@ -40,7 +40,7 @@ gem 'pg' gem 'rails_12factor', group: :production # Bootstrap 3 WYSIWYG editor with carrierwave file upload -gem 'bootsy' +gem 'bootsy', '>= 2.4.0' # Bootstrap pagination links gem 'will_paginate-bootstrap' @@ -56,10 +56,10 @@ gem "que" # for link_helpers gem "nested_form" -gem 'jquery-ui-rails' +gem 'jquery-ui-rails', '>= 6.0.0' group :development do - gem 'better_errors' + gem 'better_errors', '>= 2.8.0' gem 'binding_of_caller', :platforms=>[:mri_21] gem 'capistrano' gem 'capistrano-bundler' @@ -92,11 +92,11 @@ group :test do gem 'database_cleaner' gem 'launchy' gem 'selenium-webdriver' - gem 'cucumber-rails', :require=>false + gem 'cucumber-rails', '>= 2.1.0', :require=>false gem 'shoulda-matchers' # for Travis CI - gem 'rake' + gem 'rake', '>= 12.3.3' gem 'spork' end