From 6a8a91a274544bf8859cbfeeca0b60c224a3d815 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 23 May 2020 00:20:38 +0200 Subject: [PATCH 1/2] fix: Gemfile & Gemfile.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-569598 --- Gemfile | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Gemfile b/Gemfile index f045dc2..dfaf5bb 100644 --- a/Gemfile +++ b/Gemfile @@ -2,11 +2,11 @@ # the following line to use "http://" instead source 'https://rubygems.org' -gem "middleman", "~>3.3.8" -gem "middleman-deploy" +gem "middleman", "~> 3.3.9" +gem "middleman-deploy", ">= 1.0.0" # Live-reloading plugin -gem "middleman-livereload", "~> 3.1.0" +gem "middleman-livereload", "~> 3.1.1" # For faster file watcher updates on Windows: gem "wdm", "~> 0.1.0", :platforms => [:mswin, :mingw] From b77c150ac5876cee058adc12930ce0571da353f7 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 23 May 2020 00:20:39 +0200 Subject: [PATCH 2/2] fix: Gemfile & Gemfile.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-569598 --- Gemfile.lock | 95 +++++++++++++++++++++++++++------------------------- 1 file changed, 50 insertions(+), 45 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index 860034c..3a09e4a 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -1,7 +1,7 @@ GEM remote: https://rubygems.org/ specs: - activesupport (4.1.9) + activesupport (4.1.16) i18n (~> 0.6, >= 0.6.9) json (~> 1.7, >= 1.7.7) minitest (~> 5.1) @@ -12,11 +12,11 @@ GEM thor celluloid (0.16.0) timers (~> 4.0.0) - chunky_png (1.3.4) - coffee-script (2.3.0) + chunky_png (1.3.11) + coffee-script (2.4.1) coffee-script-source execjs - coffee-script-source (1.9.0) + coffee-script-source (1.12.2) compass (1.0.3) chunky_png (~> 1.2) compass-core (~> 1.0.2) @@ -33,35 +33,36 @@ GEM eventmachine (>= 0.12.9) http_parser.rb (~> 0.6.0) erubis (2.7.0) - eventmachine (1.0.7) - execjs (2.3.0) - ffi (1.9.6) - haml (4.0.6) + eventmachine (1.2.7) + execjs (2.7.0) + ffi (1.12.2) + haml (5.1.2) + temple (>= 0.8.0) tilt hike (1.2.3) - hitimes (1.2.2) - hooks (0.4.0) - uber (~> 0.0.4) + hitimes (2.0.0) + hooks (0.4.1) + uber (~> 0.0.14) http_parser.rb (0.6.0) i18n (0.7.0) - json (1.8.2) - kramdown (1.5.0) - listen (2.8.5) - celluloid (>= 0.15.2) + json (1.8.6) + kramdown (1.17.0) + listen (2.10.1) + celluloid (~> 0.16.0) rb-fsevent (>= 0.9.3) rb-inotify (>= 0.9) - middleman (3.3.9) + middleman (3.3.12) coffee-script (~> 2.2) compass (>= 1.0.0, < 2.0.0) compass-import-once (= 1.0.5) execjs (~> 2.0) haml (>= 4.0.5) kramdown (~> 1.2) - middleman-core (= 3.3.9) + middleman-core (= 3.3.12) middleman-sprockets (>= 3.1.2) sass (>= 3.4.0, < 4.0) uglifier (~> 2.5) - middleman-core (3.3.9) + middleman-core (3.3.12) activesupport (~> 4.1.0) bundler (~> 1.1) erubis @@ -82,36 +83,36 @@ GEM middleman-core (>= 3.0.2) multi_json (~> 1.0) rack-livereload - middleman-sprockets (3.4.1) + middleman-sprockets (3.5.0) middleman-core (>= 3.3) sprockets (~> 2.12.1) sprockets-helpers (~> 1.1.0) sprockets-sass (~> 1.3.0) - minitest (5.5.1) - multi_json (1.10.1) + minitest (5.14.1) + multi_json (1.14.1) neat (1.7.1) bourbon (>= 4.0) sass (>= 3.3) - net-sftp (2.1.2) - net-ssh (>= 2.6.5) - net-ssh (2.9.2) - padrino-helpers (0.12.4) + net-sftp (3.0.0) + net-ssh (>= 5.0.0, < 7.0.0) + net-ssh (6.0.2) + padrino-helpers (0.12.9) i18n (~> 0.6, >= 0.6.7) - padrino-support (= 0.12.4) - tilt (~> 1.4.1) - padrino-support (0.12.4) + padrino-support (= 0.12.9) + tilt (>= 1.4.1, < 3) + padrino-support (0.12.9) activesupport (>= 3.1) - ptools (1.3.2) - rack (1.6.0) - rack-livereload (0.3.15) + ptools (1.3.5) + rack (1.6.13) + rack-livereload (0.3.17) rack rack-test (0.6.3) rack (>= 1.0) - rb-fsevent (0.9.4) - rb-inotify (0.9.5) - ffi (>= 0.5.0) - sass (3.4.12) - sprockets (2.12.3) + rb-fsevent (0.10.4) + rb-inotify (0.10.1) + ffi (~> 1.0) + sass (3.4.25) + sprockets (2.12.5) hike (~> 1.2) multi_json (~> 1.0) rack (~> 1.0) @@ -121,15 +122,16 @@ GEM sprockets-sass (1.3.1) sprockets (~> 2.0) tilt (~> 1.1) - thor (0.19.1) - thread_safe (0.3.4) + temple (0.8.2) + thor (1.0.1) + thread_safe (0.3.6) tilt (1.4.1) - timers (4.0.1) + timers (4.0.4) hitimes - tzinfo (1.2.2) + tzinfo (1.2.7) thread_safe (~> 0.1) - uber (0.0.13) - uglifier (2.7.0) + uber (0.0.15) + uglifier (2.7.2) execjs (>= 0.3.0) json (>= 1.8.0) @@ -138,9 +140,12 @@ PLATFORMS DEPENDENCIES bourbon - middleman (~> 3.3.8) - middleman-deploy - middleman-livereload (~> 3.1.0) + middleman (~> 3.3.9) + middleman-deploy (>= 1.0.0) + middleman-livereload (~> 3.1.1) neat tzinfo-data wdm (~> 0.1.0) + +BUNDLED WITH + 1.17.3