From ec0a10b09fe3b4e4b9f095123f4a4edd8f4df883 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 30 Apr 2020 08:56:45 +0100 Subject: [PATCH 1/2] fix: Gemfile & Gemfile.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-JSON-567822 --- Gemfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Gemfile b/Gemfile index e29e26cdc833e..30778f1bf0498 100644 --- a/Gemfile +++ b/Gemfile @@ -17,4 +17,4 @@ gem "jekyll-coffeescript", "1.0.1" gem "jekyll-seo-tag", "2.0.0" gem "jekyll-github-metadata", "2.0.2" gem "listen", "3.0.6" -gem "activesupport", "4.2.7" +gem "activesupport", "4.2.8" From c502bdcd410d2cb42bb2d941b344a4a5ffac4ea7 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 30 Apr 2020 08:56:46 +0100 Subject: [PATCH 2/2] fix: Gemfile & Gemfile.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-JSON-567822 --- Gemfile.lock | 50 ++++++++++++++++++++++++++------------------------ 1 file changed, 26 insertions(+), 24 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index ee385b958b60a..8ae58fd95b571 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -1,9 +1,8 @@ GEM remote: https://rubygems.org/ specs: - activesupport (4.2.7) + activesupport (4.2.8) i18n (~> 0.7) - json (~> 1.7, >= 1.7.7) minitest (~> 5.1) thread_safe (~> 0.3, >= 0.3.4) tzinfo (~> 1.1) @@ -13,16 +12,18 @@ GEM execjs coffee-script-source (1.10.0) colorator (1.1.0) + concurrent-ruby (1.1.6) execjs (2.7.0) faraday (0.9.2) multipart-post (>= 1.2, < 3) - ffi (1.9.14) + ffi (1.12.2) forwardable-extended (2.6.0) gemoji (2.1.0) - html-pipeline (2.4.2) + html-pipeline (2.12.3) activesupport (>= 2) nokogiri (>= 1.4) - i18n (0.7.0) + i18n (0.9.5) + concurrent-ruby (~> 1.0) jekyll (3.2.1) colorator (~> 1.0) jekyll-sass-converter (~> 1.0) @@ -53,50 +54,51 @@ GEM jekyll-seo-tag (2.0.0) jekyll (~> 3.1) jekyll-sitemap (0.10.0) - jekyll-watch (1.5.0) - listen (~> 3.0, < 3.1) + jekyll-watch (1.5.1) + listen (~> 3.0) jemoji (0.7.0) activesupport (~> 4.0) gemoji (~> 2.0) html-pipeline (~> 2.2) jekyll (>= 3.0) - json (1.8.3) kramdown (1.11.1) liquid (3.0.6) listen (3.0.6) rb-fsevent (>= 0.9.3) rb-inotify (>= 0.9.7) mercenary (0.3.6) - mini_portile2 (2.1.0) + mini_portile2 (2.4.0) minima (1.1.0) - minitest (5.9.0) + minitest (5.14.0) multipart-post (2.0.0) - nokogiri (1.6.8) - mini_portile2 (~> 2.1.0) - pkg-config (~> 1.1.7) + nokogiri (1.10.9) + mini_portile2 (~> 2.4.0) octokit (4.3.0) sawyer (~> 0.7.0, >= 0.5.3) - pathutil (0.14.0) + pathutil (0.16.2) forwardable-extended (~> 2.6) - pkg-config (1.1.7) - rb-fsevent (0.9.7) - rb-inotify (0.9.7) - ffi (>= 0.5.0) + rb-fsevent (0.10.3) + rb-inotify (0.10.1) + ffi (~> 1.0) rouge (1.11.1) - safe_yaml (1.0.4) - sass (3.4.22) + safe_yaml (1.0.5) + sass (3.7.4) + sass-listen (~> 4.0.0) + sass-listen (4.0.0) + rb-fsevent (~> 0.9, >= 0.9.4) + rb-inotify (~> 0.9, >= 0.9.7) sawyer (0.7.0) addressable (>= 2.3.5, < 2.5) faraday (~> 0.8, < 0.10) - thread_safe (0.3.5) - tzinfo (1.2.2) + thread_safe (0.3.6) + tzinfo (1.2.7) thread_safe (~> 0.1) PLATFORMS ruby DEPENDENCIES - activesupport (= 4.2.7) + activesupport (= 4.2.8) jekyll (= 3.2.1) jekyll-coffeescript (= 1.0.1) jekyll-feed (= 0.5.1) @@ -116,4 +118,4 @@ DEPENDENCIES rouge (= 1.11.1) BUNDLED WITH - 1.11.2 + 1.17.3