From 045b216beb27ad776d0600f991b12235ea71aac0 Mon Sep 17 00:00:00 2001 From: Finn Woelm Date: Mon, 28 Oct 2019 22:54:57 +0100 Subject: [PATCH] Gem: Update nokogiri to v1.10.4 Fixes security issue: https://nvd.nist.gov/vuln/detail/CVE-2019-5477 --- Gemfile | 2 +- Gemfile.lock | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/Gemfile b/Gemfile index 647ca720..227d8577 100644 --- a/Gemfile +++ b/Gemfile @@ -41,7 +41,7 @@ gem 'devise', '~> 4.4' # Use CanCanCan for authorization (permission management) gem 'cancancan', '~> 2.1' # Nokogiri for parsing fields with errors -gem 'nokogiri', '~> 1.8.1' +gem 'nokogiri', '~> 1.10' # For simplified Rails configuration gem 'config', '~> 1.7' # Sequenced for scoped IDs diff --git a/Gemfile.lock b/Gemfile.lock index 79bee07a..648e17a3 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -312,7 +312,7 @@ GEM mime-types-data (3.2018.0812) mimemagic (0.3.2) mini_mime (1.0.1) - mini_portile2 (2.3.0) + mini_portile2 (2.4.0) minitest (5.11.3) momentjs-rails (2.20.1) railties (>= 3.1) @@ -324,8 +324,8 @@ GEM net-ssh (5.0.2) netrc (0.11.0) nio4r (2.3.1) - nokogiri (1.8.5) - mini_portile2 (~> 2.3.0) + nokogiri (1.10.4) + mini_portile2 (~> 2.4.0) notiffany (0.1.1) nenv (~> 0.1) shellany (~> 0.0) @@ -564,7 +564,7 @@ DEPENDENCIES listen (>= 3.0.5, < 3.2) lograge (~> 0.10) materialize-sass (~> 1.0.0beta) - nokogiri (~> 1.8.1) + nokogiri (~> 1.10) paperclip (~> 6.0) pg (~> 1.1) premailer-rails (~> 1.10)