Skip to content

Commit 65beeb9

Browse files
author
Vidas P
committed
Update rails, grape (CVE-2020-5267)
1 parent 7f03b0e commit 65beeb9

File tree

3 files changed

+84
-59
lines changed

3 files changed

+84
-59
lines changed

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
88
## [current]
99
### Fixed
1010
- Update puma (CVE-2020-5249)
11+
- Update rails, grape (CVE-2020-5267)
1112

1213

1314
## [0.9.7] - 2020-02-28

Gemfile

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@ gem 'mini_magick', '~> 4.9.5'
7070
gem 'nokogiri', '~> 1.10.8'
7171
gem 'omniauth', '~> 1.9.0'
7272
gem 'rack-timeout', '~> 0.5.1'
73-
gem 'rails', '~> 5.2.3'
73+
gem 'rails', '~> 5.2.4.2'
7474
gem 'rails-html-sanitizer', '~> 1.0.4'
7575
# TODO: Removing coffee-rails breaks deployment on heroku, investigate.
7676
gem 'coffee-rails', '~> 4.2.2'
@@ -86,8 +86,8 @@ gem 'sprockets', '~> 3.7.2'
8686
gem 'typhoeus', '~> 0.6.3'
8787
gem 'uglifier', '~> 4.1.18'
8888
gem 'jquery-datatables', '~> 1.10.19'
89-
gem 'grape', '~> 1.2.4'
90-
gem 'grape-entity', '~> 0.7.1'
89+
gem 'grape', '~> 1.3.1'
90+
gem 'grape-entity', '~> 0.8.0'
9191
gem 'jwt', '~> 2.2.1'
9292

9393
group :development do

Gemfile.lock

Lines changed: 80 additions & 56 deletions
Original file line numberDiff line numberDiff line change
@@ -14,43 +14,43 @@ GEM
1414
remote: https://rubygems.org/
1515
specs:
1616
ace-rails-ap (4.2)
17-
actioncable (5.2.3)
18-
actionpack (= 5.2.3)
17+
actioncable (5.2.4.2)
18+
actionpack (= 5.2.4.2)
1919
nio4r (~> 2.0)
2020
websocket-driver (>= 0.6.1)
21-
actionmailer (5.2.3)
22-
actionpack (= 5.2.3)
23-
actionview (= 5.2.3)
24-
activejob (= 5.2.3)
21+
actionmailer (5.2.4.2)
22+
actionpack (= 5.2.4.2)
23+
actionview (= 5.2.4.2)
24+
activejob (= 5.2.4.2)
2525
mail (~> 2.5, >= 2.5.4)
2626
rails-dom-testing (~> 2.0)
27-
actionpack (5.2.3)
28-
actionview (= 5.2.3)
29-
activesupport (= 5.2.3)
30-
rack (~> 2.0)
27+
actionpack (5.2.4.2)
28+
actionview (= 5.2.4.2)
29+
activesupport (= 5.2.4.2)
30+
rack (~> 2.0, >= 2.0.8)
3131
rack-test (>= 0.6.3)
3232
rails-dom-testing (~> 2.0)
3333
rails-html-sanitizer (~> 1.0, >= 1.0.2)
34-
actionview (5.2.3)
35-
activesupport (= 5.2.3)
34+
actionview (5.2.4.2)
35+
activesupport (= 5.2.4.2)
3636
builder (~> 3.1)
3737
erubi (~> 1.4)
3838
rails-dom-testing (~> 2.0)
3939
rails-html-sanitizer (~> 1.0, >= 1.0.3)
40-
activejob (5.2.3)
41-
activesupport (= 5.2.3)
40+
activejob (5.2.4.2)
41+
activesupport (= 5.2.4.2)
4242
globalid (>= 0.3.6)
43-
activemodel (5.2.3)
44-
activesupport (= 5.2.3)
45-
activerecord (5.2.3)
46-
activemodel (= 5.2.3)
47-
activesupport (= 5.2.3)
43+
activemodel (5.2.4.2)
44+
activesupport (= 5.2.4.2)
45+
activerecord (5.2.4.2)
46+
activemodel (= 5.2.4.2)
47+
activesupport (= 5.2.4.2)
4848
arel (>= 9.0)
49-
activestorage (5.2.3)
50-
actionpack (= 5.2.3)
51-
activerecord (= 5.2.3)
49+
activestorage (5.2.4.2)
50+
actionpack (= 5.2.4.2)
51+
activerecord (= 5.2.4.2)
5252
marcel (~> 0.3.1)
53-
activesupport (5.2.3)
53+
activesupport (5.2.4.2)
5454
concurrent-ruby (~> 1.0, >= 1.0.2)
5555
i18n (>= 0.7, < 2)
5656
minitest (~> 5.1)
@@ -84,7 +84,7 @@ GEM
8484
bootstrap-kaminari-views (0.0.5)
8585
kaminari (>= 0.13)
8686
rails (>= 3.1)
87-
builder (3.2.3)
87+
builder (3.2.4)
8888
bullet (6.0.2)
8989
activesupport (>= 3.0.0)
9090
uniform_notifier (~> 1.11)
@@ -123,10 +123,10 @@ GEM
123123
coffee-script-source
124124
execjs
125125
coffee-script-source (1.12.2)
126-
concurrent-ruby (1.1.5)
126+
concurrent-ruby (1.1.6)
127127
crack (0.4.3)
128128
safe_yaml (~> 1.0.0)
129-
crass (1.0.5)
129+
crass (1.0.6)
130130
daemons (1.2.6)
131131
debug_inspector (0.0.3)
132132
delayed_job (4.1.8)
@@ -149,6 +149,28 @@ GEM
149149
domain_name (0.5.20170404)
150150
unf (>= 0.0.5, < 1.0.0)
151151
dotenv (2.5.0)
152+
dry-configurable (0.11.4)
153+
concurrent-ruby (~> 1.0)
154+
dry-core (~> 0.4, >= 0.4.7)
155+
dry-equalizer (~> 0.2)
156+
dry-container (0.7.2)
157+
concurrent-ruby (~> 1.0)
158+
dry-configurable (~> 0.1, >= 0.1.3)
159+
dry-core (0.4.9)
160+
concurrent-ruby (~> 1.0)
161+
dry-equalizer (0.3.0)
162+
dry-inflector (0.2.0)
163+
dry-logic (1.0.6)
164+
concurrent-ruby (~> 1.0)
165+
dry-core (~> 0.2)
166+
dry-equalizer (~> 0.2)
167+
dry-types (1.4.0)
168+
concurrent-ruby (~> 1.0)
169+
dry-container (~> 0.3)
170+
dry-core (~> 0.4, >= 0.4.4)
171+
dry-equalizer (~> 0.3)
172+
dry-inflector (~> 0.1, >= 0.1.2)
173+
dry-logic (~> 1.0, >= 1.0.2)
152174
em-websocket (0.5.1)
153175
eventmachine (>= 0.12.9)
154176
http_parser.rb (~> 0.6.0)
@@ -188,15 +210,15 @@ GEM
188210
oauth2 (~> 1.0)
189211
globalid (0.4.2)
190212
activesupport (>= 4.2.0)
191-
grape (1.2.4)
213+
grape (1.3.1)
192214
activesupport
193215
builder
216+
dry-types (>= 1.1)
194217
mustermann-grape (~> 1.0.0)
195218
rack (>= 1.3.0)
196219
rack-accept
197-
virtus (>= 1.0.0)
198-
grape-entity (0.7.1)
199-
activesupport (>= 4.0)
220+
grape-entity (0.8.0)
221+
activesupport (>= 3.0.0)
200222
multi_json (>= 1.3.2)
201223
guard (2.16.1)
202224
formatador (>= 0.2.4)
@@ -228,7 +250,7 @@ GEM
228250
http_parser.rb (0.6.0)
229251
httparty (0.16.2)
230252
multi_xml (>= 0.5.2)
231-
i18n (1.7.0)
253+
i18n (1.8.2)
232254
concurrent-ruby (~> 1.0)
233255
ice_nine (0.11.2)
234256
iniparse (1.4.4)
@@ -295,25 +317,26 @@ GEM
295317
mime-types (3.1)
296318
mime-types-data (~> 3.2015)
297319
mime-types-data (3.2016.0521)
298-
mimemagic (0.3.3)
320+
mimemagic (0.3.4)
299321
mini_magick (4.9.5)
300322
mini_mime (1.0.2)
301323
mini_portile2 (2.4.0)
302324
mini_racer (0.2.8)
303325
libv8 (>= 6.9.411)
304-
minitest (5.13.0)
326+
minitest (5.14.0)
305327
msgpack (1.2.4)
306328
multi_json (1.14.1)
307329
multi_xml (0.6.0)
308330
multipart-post (2.1.1)
309-
mustermann (1.0.3)
310-
mustermann-grape (1.0.0)
311-
mustermann (~> 1.0.0)
331+
mustermann (1.1.1)
332+
ruby2_keywords (~> 0.0.1)
333+
mustermann-grape (1.0.1)
334+
mustermann (>= 1.0.0)
312335
nenv (0.3.0)
313336
net-ftp-list (3.2.8)
314337
netrc (0.11.0)
315338
nio4r (2.5.2)
316-
nokogiri (1.10.8)
339+
nokogiri (1.10.9)
317340
mini_portile2 (~> 2.4.0)
318341
notiffany (0.1.3)
319342
nenv (~> 0.1)
@@ -369,26 +392,26 @@ GEM
369392
public_suffix (4.0.1)
370393
puma (4.3.3)
371394
nio4r (~> 2.0)
372-
rack (2.0.8)
395+
rack (2.2.2)
373396
rack-accept (0.4.5)
374397
rack (>= 0.4)
375398
rack-livereload (0.3.17)
376399
rack
377400
rack-test (1.1.0)
378401
rack (>= 1.0, < 3)
379402
rack-timeout (0.5.1)
380-
rails (5.2.3)
381-
actioncable (= 5.2.3)
382-
actionmailer (= 5.2.3)
383-
actionpack (= 5.2.3)
384-
actionview (= 5.2.3)
385-
activejob (= 5.2.3)
386-
activemodel (= 5.2.3)
387-
activerecord (= 5.2.3)
388-
activestorage (= 5.2.3)
389-
activesupport (= 5.2.3)
403+
rails (5.2.4.2)
404+
actioncable (= 5.2.4.2)
405+
actionmailer (= 5.2.4.2)
406+
actionpack (= 5.2.4.2)
407+
actionview (= 5.2.4.2)
408+
activejob (= 5.2.4.2)
409+
activemodel (= 5.2.4.2)
410+
activerecord (= 5.2.4.2)
411+
activestorage (= 5.2.4.2)
412+
activesupport (= 5.2.4.2)
390413
bundler (>= 1.3.0)
391-
railties (= 5.2.3)
414+
railties (= 5.2.4.2)
392415
sprockets-rails (>= 2.0.0)
393416
rails-controller-testing (1.0.4)
394417
actionpack (>= 5.0.1.x)
@@ -407,9 +430,9 @@ GEM
407430
json
408431
require_all (~> 2.0)
409432
ruby-progressbar
410-
railties (5.2.3)
411-
actionpack (= 5.2.3)
412-
activesupport (= 5.2.3)
433+
railties (5.2.4.2)
434+
actionpack (= 5.2.4.2)
435+
activesupport (= 5.2.4.2)
413436
method_source
414437
rake (>= 0.8.7)
415438
thor (>= 0.19.0, < 2.0)
@@ -475,6 +498,7 @@ GEM
475498
ruby-progressbar (~> 1.7)
476499
unicode-display_width (>= 1.4.0, < 1.7)
477500
ruby-progressbar (1.10.1)
501+
ruby2_keywords (0.0.2)
478502
rubyzip (2.0.0)
479503
rufus-scheduler (3.4.2)
480504
et-orbi (~> 1.0)
@@ -548,7 +572,7 @@ GEM
548572
multi_json (>= 1.3.0)
549573
typhoeus (0.6.9)
550574
ethon (>= 0.7.1)
551-
tzinfo (1.2.5)
575+
tzinfo (1.2.6)
552576
thread_safe (~> 0.1)
553577
uglifier (4.1.18)
554578
execjs (>= 0.3.0, < 3)
@@ -612,8 +636,8 @@ DEPENDENCIES
612636
feedjira (~> 2.2)
613637
font-awesome-sass (~> 5.6.1)
614638
foreman (~> 0.86.0)
615-
grape (~> 1.2.4)
616-
grape-entity (~> 0.7.1)
639+
grape (~> 1.3.1)
640+
grape-entity (~> 0.8.0)
617641
guard (~> 2.16.1)
618642
guard-livereload (~> 2.5.2)
619643
guard-rspec (~> 4.7.3)
@@ -644,7 +668,7 @@ DEPENDENCIES
644668
puma (~> 4.3.3)
645669
rack-livereload (~> 0.3.17)
646670
rack-timeout (~> 0.5.1)
647-
rails (~> 5.2.3)
671+
rails (~> 5.2.4.2)
648672
rails-controller-testing (~> 1.0.4)
649673
rails-html-sanitizer (~> 1.0.4)
650674
rails_best_practices (~> 1.19.4)

0 commit comments

Comments
 (0)