From e659eeb0746d2b1a5bc20a659f9622b361512ae4 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 24 Aug 2023 00:28:50 +0000 Subject: [PATCH] fix: Gemfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-5851458 - https://snyk.io/vuln/SNYK-RUBY-RAILTIES-5851410 --- Gemfile | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/Gemfile b/Gemfile index 451dba63d..796edb0b1 100644 --- a/Gemfile +++ b/Gemfile @@ -2,7 +2,7 @@ source "https://rubygems.org" #don't upgrade -gem "rails", "6.0.0" +gem "rails", "6.1.7.5" ruby "2.6.5" @@ -12,14 +12,14 @@ gem "coffee-rails" gem "execjs" gem "foreman" gem "jquery-fileupload-rails" -gem "jquery-rails" +gem "jquery-rails", ">= 4.4.0" gem "minitest" gem "powder" # Pow related gem gem "pry-rails" # not in dev group in case running via prod/staging @ a training gem "puma" gem "rails-perftest" gem "rake" -gem "responders" #For Rails 4.2 # LOCKED DOWN +gem "responders" , ">= 3.0.1" #For Rails 4.2 # LOCKED DOWN gem "ruby-prof" gem "sassc-rails" gem "simplecov", require: false, group: :test @@ -52,7 +52,7 @@ group :development, :test, :mysql do gem "database_cleaner" gem "launchy" gem "poltergeist" - gem "rspec-rails", '4.0.0.beta3' # 4/26/2019: LOCKED DOWN + gem "rspec-rails", "4.0.0" # 4/26/2019: LOCKED DOWN gem "test-unit" end