From 47548d3208e0c9f246ec50174d9090b425c57451 Mon Sep 17 00:00:00 2001 From: Timur Vafin Date: Tue, 17 Oct 2017 16:07:37 +0300 Subject: [PATCH] Update nokogiri to 1.8.1 to close CVE-2017-905 (#5) URL: https://github.com/sparklemotion/nokogiri/issues/1673 Title: Nokogiri gem, via libxml, is affected by DoS and RCE vulnerabilities --- Gemfile.lock | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index 068fa3c..61da917 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -57,12 +57,12 @@ GEM jsonapi-renderer (0.1.3) loofah (2.0.3) nokogiri (>= 1.5.9) - mini_portile2 (2.2.0) + mini_portile2 (2.3.0) minitest (5.10.2) multi_json (1.12.1) multi_xml (0.6.0) - nokogiri (1.8.0) - mini_portile2 (~> 2.2.0) + nokogiri (1.8.1) + mini_portile2 (~> 2.3.0) parser (2.3.1.2) ast (~> 2.2) powerpack (0.1.1)