From 22a354a7a76c97fd29ab6e65975d9bcb0bf67957 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 4 Apr 2024 17:06:51 +0000 Subject: [PATCH] fix: Gemfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-6274386 - https://snyk.io/vuln/SNYK-RUBY-CARRIERWAVE-6483299 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-6228056 - https://snyk.io/vuln/SNYK-RUBY-RACK-6274383 - https://snyk.io/vuln/SNYK-RUBY-RACK-6274384 - https://snyk.io/vuln/SNYK-RUBY-RACK-6274385 - https://snyk.io/vuln/SNYK-RUBY-RDOC-6476871 --- Gemfile | 36 ++++++++++++++++++------------------ 1 file changed, 18 insertions(+), 18 deletions(-) diff --git a/Gemfile b/Gemfile index 998e45e..9f8ad39 100644 --- a/Gemfile +++ b/Gemfile @@ -1,27 +1,27 @@ source 'https://rubygems.org' ruby '2.1.2' -gem 'rails', '4.2.5' -gem 'sass-rails', '~> 4.0.3' +gem 'rails', '7.0.8.1' +gem 'sass-rails', '~> 5.0.8' gem 'uglifier', '>= 1.3.0' -gem 'coffee-rails', '~> 4.0.0' -gem 'jquery-rails' -gem 'turbolinks' +gem 'coffee-rails', '~> 4.2.2' +gem 'jquery-rails', '>= 4.0.4' +gem 'turbolinks', '>= 2.5.4' gem 'jbuilder', '~> 2.0' -gem 'sdoc', '~> 0.4.0', group: :doc +gem 'sdoc', '~> 1.0.0', group: :doc gem 'spring', group: :development gem 'bootstrap-sass' -gem 'devise' +gem 'devise', '>= 4.7.0' gem 'pundit' -gem 'simple_form' -gem 'slim-rails' +gem 'simple_form', '>= 4.0.0' +gem 'slim-rails', '>= 3.1.0' gem 'bootstrap3_autocomplete_input' gem 'twitter-typeahead-rails' # Application server -gem 'unicorn' -gem 'unicorn-rails' +gem 'unicorn', '>= 4.9.0' +gem 'unicorn-rails', '>= 2.2.1' # file management gem 'carrierwave', :git => 'https://github.com/carrierwaveuploader/carrierwave.git' @@ -49,17 +49,17 @@ gem 'will_paginate-bootstrap' gem 'jquery-tokeninput-rails' # Multiple file upload plugin -gem "jquery-fileupload-rails" +gem "jquery-fileupload-rails", ">= 0.4.2" gem "que" # for link_helpers gem "nested_form" -gem 'jquery-ui-rails' +gem 'jquery-ui-rails', '>= 5.0.1' group :development do - gem 'better_errors' + gem 'better_errors', '>= 2.2.0' gem 'binding_of_caller', :platforms=>[:mri_21] gem 'capistrano' gem 'capistrano-bundler' @@ -80,19 +80,19 @@ group :development do end group :development, :test do - gem 'factory_girl_rails' + gem 'factory_girl_rails', '>= 4.6.0' gem 'faker' gem 'pry-rails' gem 'pry-rescue' - gem 'rspec-rails' + gem 'rspec-rails', '>= 3.5.0' end group :test do - gem 'capybara' + gem 'capybara', '>= 2.5.0' gem 'database_cleaner' gem 'launchy' gem 'selenium-webdriver' - gem 'cucumber-rails', :require=>false + gem 'cucumber-rails', '>= 1.4.3', :require=>false gem 'shoulda-matchers' # for Travis CI