[Snyk] Fix for 4 vulnerable dependencies #3

Open
snyk-bot wants to merge 1 commit from snyk-fix-zkg3j5 into master
snyk-bot commented 2018-06-12 02:05:46 -04:00 (Migrated from github.com)

Description

This PR fixes one or more vulnerable packages in the rubygems dependencies of this project.
See the Snyk test report for more details.

Snyk Organization: atomaka

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • Gemfile.lock
    • Gemfile

Vulnerabilities that will be fixed

With an upgrade:

You can read more about Snyk's upgrade and patch logic in Snyk's documentation.

Check the changes in this PR to ensure they won't cause issues with your project.

Stay secure,
The Snyk team

#### Description This PR fixes one or more vulnerable packages in the `rubygems` dependencies of this project. See the [Snyk test report](https://snyk.io/test/github/39f5769a-2ee8-4777-a1bb-509dcee65a10/master..snyk-fix-zkg3j5) for more details. #### Snyk Project: [atomaka/link-share:Gemfile.lock](https://snyk.io/org/atomaka/project/39f5769a-2ee8-4777-a1bb-509dcee65a10) #### Snyk Organization: [atomaka](https://snyk.io/org/atomaka) #### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - Gemfile.lock - Gemfile #### Vulnerabilities that will be fixed ##### With an upgrade: - [SNYK-RUBY-NOKOGIRI-22014](https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-22014) - [SNYK-RUBY-RACKPROTECTION-22019](https://snyk.io/vuln/SNYK-RUBY-RACKPROTECTION-22019) - [SNYK-RUBY-SINATRA-22017](https://snyk.io/vuln/SNYK-RUBY-SINATRA-22017) - [SNYK-RUBY-SINATRA-22027](https://snyk.io/vuln/SNYK-RUBY-SINATRA-22027) You can read more about Snyk's upgrade and patch logic in [Snyk's documentation](https://snyk.io/docs/using-snyk/). Check the changes in this PR to ensure they won't cause issues with your project. Stay secure, The Snyk team [//]: # (snyk:metadata:{"type":"auto","packageManager":"rubygems","vulns":["SNYK-RUBY-NOKOGIRI-22014","SNYK-RUBY-RACKPROTECTION-22019","SNYK-RUBY-SINATRA-22017","SNYK-RUBY-SINATRA-22027"],"patch":[],"upgrade":["SNYK-RUBY-NOKOGIRI-22014","SNYK-RUBY-RACKPROTECTION-22019","SNYK-RUBY-SINATRA-22017","SNYK-RUBY-SINATRA-22027"],"isBreakingChange":false,"env":"prod"})
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin snyk-fix-zkg3j5:snyk-fix-zkg3j5
git checkout snyk-fix-zkg3j5

Merge

Merge the changes and update on Forgejo.
git checkout master
git merge --no-ff snyk-fix-zkg3j5
git checkout master
git merge --ff-only snyk-fix-zkg3j5
git checkout snyk-fix-zkg3j5
git rebase master
git checkout master
git merge --no-ff snyk-fix-zkg3j5
git checkout master
git merge --squash snyk-fix-zkg3j5
git checkout master
git merge --ff-only snyk-fix-zkg3j5
git checkout master
git merge snyk-fix-zkg3j5
git push origin master
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference: atomaka/link-share#3
No description provided.