From 30d1b41d69ccf7a564166cae328e460f8bf36ebf Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 4 Apr 2024 17:29:54 +0000 Subject: [PATCH] fix: Gemfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-6274386 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-6274388 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-6228056 - https://snyk.io/vuln/SNYK-RUBY-RACK-6274383 - https://snyk.io/vuln/SNYK-RUBY-RACK-6274384 - https://snyk.io/vuln/SNYK-RUBY-RACK-6274385 --- Gemfile | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/Gemfile b/Gemfile index 585f9741..576d12df 100644 --- a/Gemfile +++ b/Gemfile @@ -4,27 +4,27 @@ git_source(:github) { |repo| "https://github.com/#{repo}.git" } ruby '~> 2.5' # Bundle edge Rails instead: gem 'rails', github: 'rails/rails' -gem 'rails', '~> 5.2.3' +gem 'rails', '~> 7.0.8', '>= 7.0.8.1' # Use postgres as the database for Active Record gem 'pg', '~> 1.1' # Use Puma as the app server gem 'puma', '~> 3.12' # Use SCSS for stylesheets -gem 'sass-rails', '~> 5.0' +gem 'sass-rails', '~> 6.0', '>= 6.0.0' # Use Uglifier as compressor for JavaScript assets gem 'uglifier', '>= 1.3.0' gem 'chartkick', '~> 3.2' gem 'database_cleaner', '~> 1.7' -gem 'bootstrap', '~> 4.4.1' -gem 'jquery-rails', '~> 4.3' +gem 'bootstrap', '~> 4.5.0' +gem 'jquery-rails', '~> 4.4', '>= 4.4.0' gem 'version_sorter', '~> 2.2' -gem 'kaminari', '~> 1.1' +gem 'kaminari', '~> 1.2', '>= 1.2.1' -gem 'octicons_helper', '~> 8.5' +gem 'octicons_helper', '~> 9.0', '>= 9.0.0' gem 'pg_search', '~> 2.2' gem 'friendly_id', '~> 5.3.0' @@ -38,26 +38,26 @@ group :development, :test do # Call 'byebug' anywhere in the code to stop execution and get a debugger console gem 'byebug', platforms: [:mri, :mingw, :x64_mingw] - gem 'factory_bot_rails', '~> 5.0' + gem 'factory_bot_rails', '~> 5.2', '>= 5.2.0' end group :development do # Access an interactive console on exception pages or by calling 'console' anywhere in the code. - gem 'web-console', '>= 3.3.0' + gem 'web-console', '>= 4.0.0' gem 'listen', '>= 3.0.5', '< 3.3' # Spring speeds up development by keeping your application running in the background. Read more: https://github.com/rails/spring gem 'spring' gem 'spring-watcher-listen', '~> 2.0.0' gem 'annotate', '~> 2.7' gem 'rails-erd', '~> 1.6' - gem 'better_errors' + gem 'better_errors', '>= 2.6.0' gem 'binding_of_caller' end group :test do # Adds support for Capybara system testing and selenium driver - gem 'capybara', '>= 2.15', '< 4.0' + gem 'capybara', '>= 3.32.0', '< 4.0' gem 'selenium-webdriver' # Easy installation and use of chromedriver to run system tests with Chrome - gem 'webdrivers' + gem 'webdrivers', '>= 4.3.0' end