From 112c051364e50d8b357c64b7c6dc7e0472c305b2 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 5 Apr 2023 03:04:56 +0000 Subject: [PATCH] fix: Gemfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-ACTIONMAILER-20112 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-1290051 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-1290052 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20121 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20122 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20123 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20125 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20147 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20148 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20158 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20198 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20200 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20256 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20258 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-20264 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-2400638 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-3237231 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-3237232 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-569599 - https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-569600 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-1314522 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-20149 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-20185 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-20259 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-2960802 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERECORD-3237239 - https://snyk.io/vuln/SNYK-RUBY-ACTIVERESOURCE-568275 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-20229 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-3237242 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-3360028 - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-569598 - https://snyk.io/vuln/SNYK-RUBY-ADDRESSABLE-1316242 - https://snyk.io/vuln/SNYK-RUBY-BETTERERRORS-1583446 - https://snyk.io/vuln/SNYK-RUBY-DRAGONFLY-1298031 - https://snyk.io/vuln/SNYK-RUBY-DRAGONFLY-20193 - https://snyk.io/vuln/SNYK-RUBY-EXCON-20404 - https://snyk.io/vuln/SNYK-RUBY-EXCON-537866 - https://snyk.io/vuln/SNYK-RUBY-FFI-22037 - https://snyk.io/vuln/SNYK-RUBY-GUARDLIVERELOAD-20361 - https://snyk.io/vuln/SNYK-RUBY-I18N-72582 - https://snyk.io/vuln/SNYK-RUBY-JQUERYRAILS-20225 - https://snyk.io/vuln/SNYK-RUBY-JQUERYRAILS-450225 - https://snyk.io/vuln/SNYK-RUBY-JQUERYRAILS-565439 - https://snyk.io/vuln/SNYK-RUBY-JQUERYRAILS-575390 - https://snyk.io/vuln/SNYK-RUBY-JQUERYUIRAILS-449592 - https://snyk.io/vuln/SNYK-RUBY-JSON-560838 - https://snyk.io/vuln/SNYK-RUBY-MAIL-20244 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1055008 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1293239 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1583442 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1726792 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20214 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20245 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20277 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20292 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20299 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20367 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20368 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-20432 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-22013 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-22014 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2413994 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2620374 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2630623 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2630898 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-2840634 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-3052880 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-3357692 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-3357693 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-459107 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-534637 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-552159 - https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-72433 - https://snyk.io/vuln/SNYK-RUBY-RACK-1061917 - https://snyk.io/vuln/SNYK-RUBY-RACK-20230 - https://snyk.io/vuln/SNYK-RUBY-RACK-20399 - https://snyk.io/vuln/SNYK-RUBY-RACK-2848599 - https://snyk.io/vuln/SNYK-RUBY-RACK-2848600 - https://snyk.io/vuln/SNYK-RUBY-RACK-3356639 - https://snyk.io/vuln/SNYK-RUBY-RACK-538324 - https://snyk.io/vuln/SNYK-RUBY-RACK-569066 - https://snyk.io/vuln/SNYK-RUBY-RACK-572377 - https://snyk.io/vuln/SNYK-RUBY-RACK-72567 - https://snyk.io/vuln/SNYK-RUBY-RACKMINIPROFILER-20267 - https://snyk.io/vuln/SNYK-RUBY-RAILTIES-20454 - https://snyk.io/vuln/SNYK-RUBY-RAKE-552000 - https://snyk.io/vuln/SNYK-RUBY-RDOC-1279617 - https://snyk.io/vuln/SNYK-RUBY-RDOC-1316279 - https://snyk.io/vuln/SNYK-RUBY-REFINERYCMSCORE-20455 - https://snyk.io/vuln/SNYK-RUBY-REFINERYCMSCORE-20456 - https://snyk.io/vuln/SNYK-RUBY-REFINERYCMSCORE-20457 - https://snyk.io/vuln/SNYK-RUBY-REFINERYCMSCORE-20458 - https://snyk.io/vuln/SNYK-RUBY-SPROCKETS-22032 - https://snyk.io/vuln/SNYK-RUBY-TZINFO-2958048 - https://snyk.io/vuln/SNYK-RUBY-UGLIFIER-20236 --- Gemfile | 44 ++++++++++++++++++++++---------------------- 1 file changed, 22 insertions(+), 22 deletions(-) diff --git a/Gemfile b/Gemfile index 0aa2b3a..be42c01 100644 --- a/Gemfile +++ b/Gemfile @@ -1,6 +1,6 @@ source 'https://rubygems.org' -gem 'rails', '3.2.14' +gem 'rails', '6.1.7.3' # Bundle edge Rails instead: # gem 'rails', :git => 'git://github.com/rails/rails.git' @@ -9,34 +9,34 @@ gem 'rails', '3.2.14' # Gems used only for assets and not required # in production environments by default. group :assets do - gem 'sass-rails', '~> 3.2.3' - gem 'coffee-rails', '~> 3.2.1' + gem 'sass-rails', '~> 5.0.8' + gem 'coffee-rails', '~> 4.2.2' # See https://github.com/sstephenson/execjs#readme for more supported runtimes # gem 'therubyracer', :platforms => :ruby - gem 'uglifier', '>= 1.0.3' + gem 'uglifier', '>= 2.7.2' end -gem 'jquery-rails' -gem 'jquery-ui-rails' +gem 'jquery-rails', '>= 4.4.0' +gem 'jquery-ui-rails', '>= 6.0.0' # Refinery CMS -gem 'refinerycms', '~> 2.1.0' -gem 'refinerycms-nested_models' +gem 'refinerycms', '~> 4.0.0' +gem 'refinerycms-nested_models', '>= 0.1.0' gem 'refinerycms-copywriting' # Optionally, specify additional Refinery CMS Extensions here: -gem 'refinerycms-acts-as-indexed', '~> 1.0.0' +gem 'refinerycms-acts-as-indexed', '~> 3.0.0' gem 'mysql2' gem 'rack-rewrite' -gem 'rack' -gem 'rack-mini-profiler' +gem 'rack', '>= 3.0.0' +gem 'rack-mini-profiler', '>= 0.10.1' gem 'unicorn' gem 'awesome_nested_set' -gem 'friendly_id' -gem 'thinking-sphinx', '~> 3.1.0' +gem 'friendly_id', '>= 5.0.3' +gem 'thinking-sphinx', '~> 3.1.3' gem 'will_paginate', '~> 3.0' group :test do @@ -44,7 +44,7 @@ group :test do end group :development do - gem 'better_errors' + gem 'better_errors', '>= 2.8.0' gem 'binding_of_caller' gem 'pry-rails' gem 'awesome_print' @@ -53,14 +53,14 @@ end group :test, :development do gem 'spork-rails' - gem 'rspec-rails' + gem 'rspec-rails', '>= 3.5.0' # gem 'rb-fsevent', :require => false if RUBY_PLATFORM =~ /darwin/i gem 'guard' gem 'guard-rails' gem 'guard-rspec' gem 'guard-spork' gem 'guard-bundler', require: false - gem 'guard-livereload' + gem 'guard-livereload', '>= 2.5.2' gem 'factory_girl_rails' gem 'capybara' gem 'faker' @@ -68,8 +68,8 @@ end group :assets do gem 'autoprefixer-rails' - gem 'compass-rails', '~> 2.0.0' - gem 'compass', '~> 1.0.0.alpha.21' + gem 'compass-rails', '~> 3.0.0' + gem 'compass', '~> 1.0.3.0.0' gem 'susy' gem 'breakpoint' end @@ -81,10 +81,10 @@ gem 'shortcode' # Deployment -gem 'capistrano', '~> 3.4', require: false -gem 'capistrano-rails', '~> 1.1', require: false -gem 'capistrano-bundler', '~> 1.1', require: false -gem 'capistrano-rvm', '~> 0.1', require: false +gem 'capistrano', '~> 3.5', '>= 3.5.0', require: false +gem 'capistrano-rails', '~> 1.1', '>= 1.1.3', require: false +gem 'capistrano-bundler', '~> 1.1', '>= 1.1.4', require: false +gem 'capistrano-rvm', '~> 0.1', '>= 0.1.2', require: false gem 'whenever', :require => false gem 'capistrano-passenger', '~> 0.2.0', require: false