[Snyk] Fix for 7 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `rubygems` dependencies of this project.
As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.
Changes included in this Merge Request
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- Gemfile
⚠ ️ Warning
Failed to update the Gemfile.lock, please update manually before merging.
Vulnerabilities that will be fixed
With an upgrade:
Severity | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|
Cross-site Request Forgery (CSRF) SNYK-RUBY-ACTIONPACK-569599 |
Yes | No Known Exploit | |
Information Exposure SNYK-RUBY-ACTIONPACK-569600 |
Yes | No Known Exploit | |
Cross-site Request Forgery (CSRF) SNYK-RUBY-ACTIONVIEW-569601 |
Yes | No Known Exploit | |
Deserialization of Untrusted Data SNYK-RUBY-ACTIVESUPPORT-569598 |
Yes | No Known Exploit | |
HTTP Request Smuggling SNYK-RUBY-PUMA-570205 |
No | No Known Exploit | |
HTTP Request Smuggling SNYK-RUBY-PUMA-570206 |
No | No Known Exploit | |
Directory Traversal SNYK-RUBY-RACK-569066 |
No | No Known Exploit |
Check the changes in this Merge Request to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 [View latest project report](https://app.snyk.io/org/Monorepo 1 (open to all)/project/6ab279c1-83db-4d1b-9fad-44ced4a6e6a4)
[//]: # (snyk:metadata:{"prId":"5bfe2cee-4a6f-4d28-ad0f-cfd6f77a5389","dependencies":[{"name":"administrate","from":"0.8.1","to":"0.10.0"},{"name":"apartment","from":"2.0.0","to":"2.0.0"},{"name":"bullet","from":"5.5.1","to":"5.5.1"},{"name":"capybara-webkit","from":"1.14.0","to":"1.14.0"},{"name":"delayed_job_active_record","from":"4.1.2","to":"4.1.3"},{"name":"devise","from":"4.3.0","to":"4.4.2"},{"name":"devise_cas_authenticatable","from":"1.10.0","to":"1.10.0"},{"name":"dotenv-rails","from":"2.2.1","to":"2.2.2"},{"name":"factory_bot_rails","from":"4.10.0","to":"4.10.0"},{"name":"formulaic","from":"0.4.0","to":"0.4.0"},{"name":"foundation-rails","from":"6.3.0.0","to":"6.3.0.0"},{"name":"jquery-rails","from":"4.3.1","to":"4.3.1"},{"name":"jquery-ui-rails","from":"6.0.1","to":"6.0.1"},{"name":"puma","from":"3.9.1","to":"3.12.6"},{"name":"pundit","from":"1.1.0","to":"1.1.0"},{"name":"rack-canonical-host","from":"0.2.3","to":"0.2.3"},{"name":"rack-mini-profiler","from":"0.10.5","to":"0.10.5"},{"name":"rails","from":"5.1.1","to":"5.2.4.3"},{"name":"rspec-rails","from":"3.6.0","to":"3.6.0"},{"name":"sass-rails","from":"5.0.6","to":"5.0.6"},{"name":"scenic","from":"1.4.0","to":"1.4.0"},{"name":"shoulda-matchers","from":"3.1.1","to":"3.1.1"},{"name":"simple_form","from":"3.5.0","to":"4.0.0"},{"name":"skylight","from":"1.3.1","to":"1.3.1"},{"name":"spring","from":"2.0.2","to":"2.0.2"},{"name":"spring-commands-rspec","from":"1.0.4","to":"1.0.4"},{"name":"sprockets","from":"3.7.2","to":"3.7.2"},{"name":"sprockets-es6","from":"0.9.2","to":"0.9.2"},{"name":"title","from":"0.0.7","to":"0.0.7"},{"name":"web-console","from":"3.5.1","to":"3.5.1"}],"packageManager":"rubygems","projectPublicId":"6ab279c1-83db-4d1b-9fad-44ced4a6e6a4","projectUrl":"https://app.snyk.io/org/Monorepo 1 (open to all)/project/6ab279c1-83db-4d1b-9fad-44ced4a6e6a4?utm_source=gitlab&utm_medium=fix-pr","type":"auto","patch":[],"vulns":["SNYK-RUBY-ACTIONPACK-569599","SNYK-RUBY-ACTIONPACK-569600","SNYK-RUBY-ACTIONVIEW-569601","SNYK-RUBY-ACTIVESUPPORT-569598","SNYK-RUBY-PUMA-570205","SNYK-RUBY-PUMA-570206","SNYK-RUBY-RACK-569066"],"upgrade":["SNYK-RUBY-ACTIONPACK-569599","SNYK-RUBY-ACTIONPACK-569600","SNYK-RUBY-ACTIONVIEW-569601","SNYK-RUBY-ACTIVESUPPORT-569598","SNYK-RUBY-PUMA-570205","SNYK-RUBY-PUMA-570206","SNYK-RUBY-RACK-569066"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["pr-warning-shown"]})