From 9d7bb9d8c2631a9bd781fa7793fbcfc4fdbf71b8 Mon Sep 17 00:00:00 2001 From: Stan Hu Date: Mon, 22 Apr 2019 13:59:15 -0700 Subject: [PATCH] Bump Nokogiri to 1.10.3 This pulls in a fix for libxslt that addresses CVE-2019-11068: https://github.com/sparklemotion/nokogiri/releases --- Gemfile | 2 +- Gemfile.lock | 4 ++-- qa/Gemfile | 2 +- qa/Gemfile.lock | 4 ++-- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/Gemfile b/Gemfile index eaaf8125009..e0f892e8929 100644 --- a/Gemfile +++ b/Gemfile @@ -129,7 +129,7 @@ gem 'asciidoctor-plantuml', '0.0.8' gem 'rouge', '~> 3.1' gem 'truncato', '~> 0.7.11' gem 'bootstrap_form', '~> 4.2.0' -gem 'nokogiri', '~> 1.10.1' +gem 'nokogiri', '~> 1.10.3' gem 'escape_utils', '~> 1.1' # Calendar rendering diff --git a/Gemfile.lock b/Gemfile.lock index ba4418cd8b3..d214892eed7 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -494,7 +494,7 @@ GEM net-ssh (5.0.1) netrc (0.11.0) nio4r (2.3.1) - nokogiri (1.10.2) + nokogiri (1.10.3) mini_portile2 (~> 2.4.0) nokogumbo (1.5.0) nokogiri @@ -1104,7 +1104,7 @@ DEPENDENCIES nakayoshi_fork (~> 0.0.4) net-ldap net-ssh (~> 5.0) - nokogiri (~> 1.10.1) + nokogiri (~> 1.10.3) oauth2 (~> 1.4) octokit (~> 4.9) omniauth (~> 1.8) diff --git a/qa/Gemfile b/qa/Gemfile index 38e95ba2d65..64215b24cf1 100644 --- a/qa/Gemfile +++ b/qa/Gemfile @@ -7,6 +7,6 @@ gem 'rake', '~> 12.3.0' gem 'rspec', '~> 3.7' gem 'selenium-webdriver', '~> 3.12' gem 'airborne', '~> 0.2.13' -gem 'nokogiri', '~> 1.10.1' +gem 'nokogiri', '~> 1.10.3' gem 'rspec-retry', '~> 0.6.1' gem 'faker', '~> 1.6', '>= 1.6.6' diff --git a/qa/Gemfile.lock b/qa/Gemfile.lock index 9d3d42fb6ae..a06c88b6f0a 100644 --- a/qa/Gemfile.lock +++ b/qa/Gemfile.lock @@ -49,7 +49,7 @@ GEM mini_portile2 (2.4.0) minitest (5.11.1) netrc (0.11.0) - nokogiri (1.10.2) + nokogiri (1.10.3) mini_portile2 (~> 2.4.0) pry (0.11.3) coderay (~> 1.1.0) @@ -102,7 +102,7 @@ DEPENDENCIES capybara (~> 2.16.1) capybara-screenshot (~> 1.0.18) faker (~> 1.6, >= 1.6.6) - nokogiri (~> 1.10.1) + nokogiri (~> 1.10.3) pry-byebug (~> 3.5.1) rake (~> 12.3.0) rspec (~> 3.7)