Skip to content

[Snyk] Fix for 1 vulnerabilities

Omri Negri requested to merge snyk-fix-62d4bff766fd26fd02cfe3b9591deeda into master

Snyk has created this PR to fix one or more vulnerable packages in the `rubygems` dependencies of this project.

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

Changes included in this Merge Request

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • Gemfile
Warning
Failed to update the Gemfile.lock, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-WEBSOCKETEXTENSIONS-570830
No Proof of Concept

Check the changes in this Merge Request to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 [View latest project report](https://app.snyk.io/org/Monorepo 1 (open to all)/project/6ab279c1-83db-4d1b-9fad-44ced4a6e6a4)

🛠 [Adjust project settings](https://app.snyk.io/org/Monorepo 1 (open to all)/project/6ab279c1-83db-4d1b-9fad-44ced4a6e6a4/settings)

📚 Read more about Snyk's upgrade and patch logic

[//]: # (snyk:metadata:{"prId":"0376fe2a-99a1-4209-806b-612ed4f4be30","dependencies":[{"name":"rails","from":"5.1.1","to":"5.1.1"},{"name":"title","from":"0.0.7","to":"0.0.7"}],"packageManager":"rubygems","projectPublicId":"6ab279c1-83db-4d1b-9fad-44ced4a6e6a4","projectUrl":"https://app.snyk.io/org/Monorepo 1 (open to all)/project/6ab279c1-83db-4d1b-9fad-44ced4a6e6a4?utm_source=gitlab&utm_medium=fix-pr","type":"auto","patch":[],"vulns":["SNYK-RUBY-WEBSOCKETEXTENSIONS-570830"],"upgrade":["SNYK-RUBY-WEBSOCKETEXTENSIONS-570830"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["pr-warning-shown"]})

Merge request reports