From 2e56064095527ab98b6dc78e0194bca371cb8a65 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 21 Jun 2025 03:45:14 +0000 Subject: [PATCH] fix: Gemfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-SIDEKIQ-1090607 - https://snyk.io/vuln/SNYK-RUBY-SIDEKIQ-1729733 - https://snyk.io/vuln/SNYK-RUBY-SIDEKIQ-2359050 - https://snyk.io/vuln/SNYK-RUBY-SIDEKIQ-5885107 - https://snyk.io/vuln/SNYK-RUBY-SPROCKETS-22032 - https://snyk.io/vuln/SNYK-RUBY-TZINFO-2958048 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-569156 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-569598 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20432 - https://snyk.io/vuln/SNYK-RUBY-RACKCONTRIB-7148535 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-2960802 - https://snyk.io/vuln/SNYK-RUBY-RACK-2848599 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1293239 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-6056551 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-6056552 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-6056553 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-6056554 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-6056555 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-7164639 - https://snyk.io/vuln/SNYK-RUBY-RAKE-552000 - https://snyk.io/vuln/SNYK-RUBY-JSON-560838 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-8732769 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-8732779 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-534637 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20367 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20368 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-22014 - https://snyk.io/vuln/SNYK-RUBY-OMNIAUTH-174820 - https://snyk.io/vuln/SNYK-RUBY-RACK-10074187 - https://snyk.io/vuln/SNYK-RUBY-RACK-9398129 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-569599 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-569600 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-560837 - https://snyk.io/vuln/SNYK-RUBY-RACK-572377 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168647 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2840634 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2413994 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-459107 - https://snyk.io/vuln/SNYK-RUBY-RDOC-1279617 - https://snyk.io/vuln/SNYK-RUBY-RACK-1061917 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-552159 - https://snyk.io/vuln/SNYK-RUBY-OAUTH-1012727 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-2803851 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-1290052 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-1080913 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-20270 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-3237239 - https://snyk.io/vuln/SNYK-RUBY-ADDRESSABLE-1316242 - https://snyk.io/vuln/SNYK-RUBY-I18N-72582 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-3168317 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1726792 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-22013 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2620374 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2630623 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2630898 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-3052880 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-72433 - https://snyk.io/vuln/SNYK-RUBY-OMNIAUTH-22012 - https://snyk.io/vuln/SNYK-RUBY-OMNIAUTH-2987513 - https://snyk.io/vuln/SNYK-RUBY-RACK-2848600 - https://snyk.io/vuln/SNYK-RUBY-RACK-3356639 - https://snyk.io/vuln/SNYK-RUBY-RACK-569066 - https://snyk.io/vuln/SNYK-RUBY-RACK-6274385 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168646 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-1290051 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-569601 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-2400638 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-474102 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20299 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-9510795 - https://snyk.io/vuln/SNYK-RUBY-RACK-8720151 - https://snyk.io/vuln/SNYK-RUBY-RDOC-1316279 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-8220162 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-8220268 - https://snyk.io/vuln/SNYK-RUBY-RACK-9058602 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1583442 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-2935879 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-3357693 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-6228056 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-20271 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-3360028 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-22023 - https://snyk.io/vuln/SNYK-RUBY-RACK-72567 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-22025 - https://snyk.io/vuln/SNYK-RUBY-LOOFAH-72548 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168316 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-3237231 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-3237232 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-3237242 - https://snyk.io/vuln/SNYK-RUBY-GLOBALID-3237234 - https://snyk.io/vuln/SNYK-RUBY-RACK-3237240 - https://snyk.io/vuln/SNYK-RUBY-RACK-538324 - https://snyk.io/vuln/SNYK-RUBY-RACK-6274383 - https://snyk.io/vuln/SNYK-RUBY-RACK-6274384 - https://snyk.io/vuln/SNYK-RUBY-RACKPROTECTION-22019 - https://snyk.io/vuln/SNYK-RUBY-RAILTIES-20454 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-9510789 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-5741907 - https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-632514 - https://snyk.io/vuln/SNYK-RUBY-RDOC-6476871 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-9789079 - https://snyk.io/vuln/SNYK-RUBY-ERUBIS-20482 - https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168648 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1055008 - https://snyk.io/vuln/SNYK-RUBY-RACK-10074188 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-8453714 --- Gemfile | 74 ++++++++++++++++++++++++++++----------------------------- 1 file changed, 37 insertions(+), 37 deletions(-) diff --git a/Gemfile b/Gemfile index c66453a..0f0748f 100644 --- a/Gemfile +++ b/Gemfile @@ -1,52 +1,52 @@ source 'https://rubygems.org' -gem 'rails', '4.2.6' +gem 'rails', '7.1.0' gem 'pg', '~> 0.15' -gem 'sprockets', '3.6.3' +gem 'sprockets', '4.2.0' gem 'sass-rails', '~> 5.0' gem 'uglifier', '>= 1.3.0' -gem 'coffee-rails', '~> 4.1.0' -gem 'jquery-rails' -gem 'slim-rails' +gem 'coffee-rails', '~> 4.2.2' +gem 'jquery-rails', '>= 4.2.2' +gem 'slim-rails', '>= 3.1.2' gem 'turbolinks' -gem 'jbuilder', '~> 2.0' -gem 'sdoc', '~> 0.4.0', group: :doc +gem 'jbuilder', '~> 2.6', '>= 2.6.4' +gem 'sdoc', '~> 1.0.0', group: :doc gem 'bootstrap-sass', '~> 3.3.6' gem 'autoprefixer-rails' -gem 'devise' +gem 'devise', '>= 4.7.0' gem 'faker' -gem 'carrierwave' +gem 'carrierwave', '>= 1.0.0' gem 'remotipart' gem 'cocoon' gem 'private_pub' -gem 'skim' -gem 'gon' -gem 'responders' -gem 'omniauth' -gem 'omniauth-facebook' -gem 'omniauth-twitter' -gem 'pundit' -gem 'doorkeeper' -gem 'active_model_serializers' +gem 'skim', '>= 0.11.0' +gem 'gon', '>= 6.2.0' +gem 'responders', '>= 3.0.0' +gem 'omniauth', '>= 2.1.0' +gem 'omniauth-facebook', '>= 5.0.0' +gem 'omniauth-twitter', '>= 1.3.0' +gem 'pundit', '>= 2.0.0' +gem 'doorkeeper', '>= 4.2.5' +gem 'active_model_serializers', '>= 0.10.14' gem 'oj' gem 'oj_mimic_json' gem 'sidekiq' -gem 'sinatra', require: false +gem 'sinatra', '>= 2.0.0', require: false gem 'whenever' gem 'dotenv' gem 'dotenv-deployment', require: 'dotenv/deployment' gem 'mysql2' # Don't worry, it's for Sphinx only! -gem 'thinking-sphinx' +gem 'thinking-sphinx', '>= 3.3.0' # gem 'unicorn' -gem 'thin' +gem 'thin', '>= 1.7.1' group :development, :test do gem 'byebug', '~>8.0' - gem 'rspec-rails', '~> 3.0' - gem 'factory_girl_rails', '~> 4.0' + gem 'rspec-rails', '~> 3.6', '>= 3.6.0' + gem 'factory_girl_rails', '~> 4.8', '>= 4.8.0' gem 'spring-commands-rspec' gem 'guard-rspec' @@ -59,38 +59,38 @@ group :development, :test do end group :test do - gem 'shoulda-matchers', '~> 3.1' - gem 'capybara' + gem 'shoulda-matchers', '~> 3.1', '>= 3.1.2' + gem 'capybara', '>= 2.8.0' gem 'launchy' gem 'database_cleaner' - gem 'capybara-webkit' - gem 'capybara-email' + gem 'capybara-webkit', '>= 1.12.0' + gem 'capybara-email', '>= 3.0.1' gem 'json_spec' - gem 'test_after_commit' + gem 'test_after_commit', '>= 1.2.1' end group :development do - gem 'web-console', '~> 2.0' + gem 'web-console', '~> 3.0', '>= 3.0.0' gem 'pry' gem 'pry-rails' gem 'pry-byebug' - gem 'better_errors' - gem 'meta_request' + gem 'better_errors', '>= 2.2.0' + gem 'meta_request', '>= 0.8.0' gem 'quiet_assets' gem 'rubocop', require: false - gem 'rails_best_practices' + gem 'rails_best_practices', '>= 1.18.0' gem 'spring' - gem 'letter_opener' + gem 'letter_opener', '>= 1.5.0' - gem 'capistrano', require: false - gem 'capistrano-bundler', require: false - gem 'capistrano-rails', require: false + gem 'capistrano', '>= 3.7.0', require: false + gem 'capistrano-bundler', '>= 1.2.0', require: false + gem 'capistrano-rails', '>= 1.2.0', require: false gem 'capistrano-rvm', require: false - gem 'capistrano-sidekiq', require: false + gem 'capistrano-sidekiq', '>= 0.10.0', require: false gem 'capistrano3-unicorn', require: false end