Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Automated Bundle Update #6

Merged
merged 1 commit into from Dec 20, 2019
Merged

Conversation

sobanakram
Copy link
Owner

Gems brought up-to-date with ❤️ by Unwrappr.
See individual annotations below for details.

@@ -1,38 +1,38 @@
GEM
remote: https://rubygems.org/
specs:
actioncable (6.0.0)
actionpack (= 6.0.0)
actioncable (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

activerecord (= 6.0.0)
activestorage (= 6.0.0)
activesupport (= 6.0.0)
actionmailbox (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

actionpack (= 6.0.0)
actionview (= 6.0.0)
activejob (= 6.0.0)
actionmailer (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

actionview (= 6.0.0)
activesupport (= 6.0.0)
rack (~> 2.0)
actionpack (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

activerecord (= 6.0.0)
activestorage (= 6.0.0)
activesupport (= 6.0.0)
actiontext (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nokogiri (>= 1.8.5)
actionview (6.0.0)
activesupport (= 6.0.0)
actionview (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@@ -44,61 +44,60 @@ GEM
jsonapi-renderer (>= 0.1.1.beta1, < 0.3)
active_storage_base64 (1.0.0)
rails (~> 6.0)
activeadmin (2.3.1)
activeadmin (2.6.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

sprockets-es6 (~> 0.9, >= 0.9.2)
activejob (6.0.0)
activesupport (= 6.0.0)
activejob (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

actionpack (= 6.0.0)
activejob (= 6.0.0)
activerecord (= 6.0.0)
activemodel (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

activerecord (= 6.0.0)
activemodel (6.0.2.1)
activesupport (= 6.0.2.1)
activerecord (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

activerecord (6.0.2.1)
activemodel (= 6.0.2.1)
activesupport (= 6.0.2.1)
activestorage (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

marcel (~> 0.3.1)
activesupport (6.0.0)
activesupport (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

addressable (2.7.0)
public_suffix (>= 2.0.2, < 5.0)
airbrussh (1.3.4)
airbrussh (1.4.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

airbrussh

Minor version upgrade 📈🔶 1.3.4 → 1.4.0

[change-log, source-code]

Commits

A change of 2 commits. See the full changes on the compare page.

These are the individual commits:

sshkit (>= 1.6.1, != 1.7.0)
annotate (3.0.2)
annotate (3.0.3)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

apipie-rails (0.5.16)
rails (>= 4.1)
arbre (1.2.1)
activesupport (>= 3.0.0)
ast (2.4.0)
aws-eventstream (1.0.3)
aws-partitions (1.219.0)
aws-sdk-core (3.68.0)
aws-partitions (1.258.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

aws-partitions

Minor version upgrade 📈🔶 1.219.0 → 1.258.0

[change-log, source-code]

aws-partitions (1.219.0)
aws-sdk-core (3.68.0)
aws-partitions (1.258.0)
aws-sdk-core (3.86.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

aws-sdk-core

Minor version upgrade 📈🔶 3.68.0 → 3.86.0

[change-log, source-code]

aws-sigv4 (~> 1.1)
jmespath (~> 1.0)
aws-sdk-kms (1.24.0)
aws-sdk-core (~> 3, >= 3.61.1)
aws-sdk-kms (1.27.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

aws-sigv4 (~> 1.1)
aws-sdk-s3 (1.48.0)
aws-sdk-core (~> 3, >= 3.61.1)
aws-sdk-s3 (1.60.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@@ -107,10 +106,6 @@ GEM
descendants_tracker (~> 0.0.4)
ice_nine (~> 0.11.0)
thread_safe (~> 0.3, >= 0.3.1)
babel-source (5.8.35)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

babel-source

Gem removed 🔥

[change-log, source-code]

@@ -107,10 +106,6 @@ GEM
descendants_tracker (~> 0.0.4)
ice_nine (~> 0.11.0)
thread_safe (~> 0.3, >= 0.3.1)
babel-source (5.8.35)
babel-transpiler (0.7.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

babel-transpiler

Gem removed 🔥

[change-log, source-code]

@@ -121,7 +116,7 @@ GEM
bootsnap (1.3.2)
msgpack (~> 1.0)
brakeman (4.4.0)
builder (3.2.3)
builder (3.2.4)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

builder

Patch version upgrade 📈🔹 3.2.3 → 3.2.4

[change-log, source-code]

@@ -153,7 +148,7 @@ GEM
concurrent-ruby (1.1.5)
crack (0.4.3)
safe_yaml (~> 1.0.0)
crass (1.0.4)
crass (1.0.5)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

crass

Patch version upgrade 📈🔹 1.0.4 → 1.0.5

[change-log, source-code]

Commits

A change of 4 commits. See the full changes on the compare page.

These are the individual commits:

@@ -182,7 +177,7 @@ GEM
railties (>= 3.0.0)
faker (1.7.3)
i18n (~> 0.5)
ffi (1.11.1)
ffi (1.11.3)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@@ -198,23 +193,23 @@ GEM
i18n (0.9.5)
concurrent-ruby (~> 1.0)
ice_nine (0.11.2)
image_processing (1.9.3)
image_processing (1.10.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

image_processing

Minor version upgrade 📈🔶 1.9.3 → 1.10.0

[change-log, source-code]

Commits

A change of 4 commits. See the full changes on the compare page.

These are the individual commits:

mini_magick (>= 4.9.5, < 5)
ruby-vips (>= 2.0.13, < 3)
inherited_resources (1.11.0)
actionpack (>= 5.0, < 6.1)
has_scope (~> 0.6)
railties (>= 5.0, < 6.1)
responders (>= 2, < 4)
jaro_winkler (1.5.3)
jaro_winkler (1.5.4)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

jaro_winkler

Patch version upgrade 📈🔹 1.5.3 → 1.5.4

[change-log, source-code]

Commits

A change of 4 commits. See the full changes on the compare page.

These are the individual commits:

jbuilder (2.9.1)
activesupport (>= 4.2.0)
jmespath (1.4.0)
jquery-rails (4.3.5)
rails-dom-testing (>= 1, < 3)
railties (>= 4.2.0)
thor (>= 0.14, < 2.0)
json (2.2.0)
json (2.3.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

json

Minor version upgrade 📈🔶 2.2.0 → 2.3.0

[change-log, source-code]

@@ -236,7 +231,7 @@ GEM
listen (3.0.8)
rb-fsevent (~> 0.9, >= 0.9.4)
rb-inotify (~> 0.9, >= 0.9.7)
loofah (2.3.0)
loofah (2.4.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

loofah

Minor version upgrade 📈🔶 2.3.0 → 2.4.0

[change-log, source-code]

🎉 Patched vulnerabilities:

Commits

A change of 19 commits. See the full changes on the compare page.

These are the first 10 commits:

@@ -250,25 +245,25 @@ GEM
method_source (0.9.2)
mime-types (3.3)
mime-types-data (~> 3.2015)
mime-types-data (3.2019.0904)
mime-types-data (3.2019.1009)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mime-types-data

Patch version upgrade 📈🔹 3.2019.0904 → 3.2019.1009

[change-log, source-code]

Commits

A change of 3 commits. See the full changes on the compare page.

These are the individual commits:

mimemagic (0.3.3)
mini_magick (4.9.5)
mini_mime (1.0.2)
mini_portile2 (2.4.0)
minitest (5.12.2)
minitest (5.13.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

msgpack (1.3.1)
mysql2 (0.5.2)
mysql2 (0.5.3)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

net-scp (2.0.0)
net-ssh (>= 2.6.5, < 6.0.0)
net-ssh (5.2.0)
netrc (0.11.0)
nio4r (2.5.2)
nokogiri (1.10.4)
nokogiri (1.10.7)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nokogiri

Patch version upgrade 📈🔹 1.10.4 → 1.10.7

[change-log, source-code]

🎉 Patched vulnerabilities:

Commits

A change of 16 commits. See the full changes on the compare page.

These are the first 10 commits:

mini_portile2 (~> 2.4.0)
oj (3.9.1)
oj (3.10.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

oj

Minor version upgrade 📈🔶 3.9.1 → 3.10.0

[change-log, source-code]

Commits

A change of 20 commits. See the full changes on the compare page.

These are the first 10 commits:

orm_adapter (0.5.0)
parallel (1.17.0)
parser (2.6.4.1)
parallel (1.19.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

parallel (1.17.0)
parser (2.6.4.1)
parallel (1.19.1)
parser (2.6.5.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

parser

Patch version upgrade 📈🔹 2.6.4.1 → 2.6.5.0

[change-log, source-code]

Commits

A change of 8 commits. See the full changes on the compare page.

These are the individual commits:

@@ -277,34 +272,34 @@ GEM
activerecord (>= 5.0)
psych (3.1.0)
public_suffix (4.0.1)
puma (4.2.0)
puma (4.3.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

puma

Minor version upgrade 📈🔶 4.2.0 → 4.3.1

[change-log, source-code]

🎉 Patched vulnerabilities:

  • CVE-2019-16770
    Keepalive thread overload/DoS in puma

    CVSS V2: 6.8 high
    URL: GHSA-7xx3-m584-x994

    A poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough.

nio4r (~> 2.0)
rack (2.0.7)
rack (2.0.8)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

rack

Patch version upgrade 📈🔹 2.0.7 → 2.0.8

[change-log, source-code]

🎉 Patched vulnerabilities:

  • CVE-2019-16782
    Possible information leak / session hijack vulnerability

    URL: GHSA-hrqr-hxpp-chr3

    There's a possible information leak / session hijack vulnerability in Rack. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison. Impact: The session id stored in a cookie is the same id that is used when querying the backing session storage engine. Most storage mechanisms (for example a database) use some sort of indexing in order to speed up the lookup of that id. By carefully timing requests and session lookup failures, an attacker may be able to perform a timing attack to determine an existing session id and hijack that session.

Commits

A change of 14 commits. See the full changes on the compare page.

These are the first 10 commits:

activerecord (= 6.0.0)
activestorage (= 6.0.0)
activesupport (= 6.0.0)
rails (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

sprockets-rails (>= 2.0.0)
rails-dom-testing (2.0.3)
activesupport (>= 4.2.0)
nokogiri (>= 1.6)
rails-html-sanitizer (1.2.0)
loofah (~> 2.2, >= 2.2.2)
rails-html-sanitizer (1.3.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

rails-html-sanitizer

Minor version upgrade 📈🔶 1.2.0 → 1.3.0

[change-log, source-code]

Commits

A change of 4 commits. See the full changes on the compare page.

These are the individual commits:

railties (6.0.0)
actionpack (= 6.0.0)
activesupport (= 6.0.0)
railties (6.0.2.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

method_source
rake (>= 0.8.7)
thor (>= 0.20.3, < 2.0)
rainbow (3.0.0)
rake (12.3.3)
rake (13.0.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@@ -347,33 +342,33 @@ GEM
netrc (~> 0.8)
rspec-core (3.8.2)
rspec-support (~> 3.8.0)
rspec-expectations (3.8.4)
rspec-expectations (3.8.6)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

diff-lcs (>= 1.2.0, < 2.0)
rspec-support (~> 3.8.0)
rspec-mocks (3.8.1)
rspec-mocks (3.8.2)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

rspec-mocks

Patch version upgrade 📈🔹 3.8.1 → 3.8.2

[change-log, source-code]

Commits

A change of 6 commits. See the full changes on the compare page.

These are the individual commits:

diff-lcs (>= 1.2.0, < 2.0)
rspec-support (~> 3.8.0)
rspec-rails (3.8.2)
rspec-rails (3.8.3)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

actionpack (>= 3.0)
activesupport (>= 3.0)
railties (>= 3.0)
rspec-core (~> 3.8.0)
rspec-expectations (~> 3.8.0)
rspec-mocks (~> 3.8.0)
rspec-support (~> 3.8.0)
rspec-support (3.8.2)
rubocop (0.74.0)
rspec-support (3.8.3)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

rspec-support (3.8.2)
rubocop (0.74.0)
rspec-support (3.8.3)
rubocop (0.78.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

jaro_winkler (~> 1.5.1)
parallel (~> 1.10)
parser (>= 2.6)
rainbow (>= 2.2.2, < 4.0)
ruby-progressbar (~> 1.7)
unicode-display_width (>= 1.4.0, < 1.7)
rubocop-rails (2.3.2)
rubocop-rails (2.4.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

rack (>= 1.1)
rubocop (>= 0.72.0)
ruby-progressbar (1.10.1)
ruby-vips (2.0.15)
ruby-vips (2.0.16)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ruby-vips

Patch version upgrade 📈🔹 2.0.15 → 2.0.16

[change-log, source-code]

Commits

A change of 15 commits. See the full changes on the compare page.

These are the first 10 commits:

@@ -396,13 +391,9 @@ GEM
spring-watcher-listen (2.0.1)
listen (>= 2.7, < 4.0)
spring (>= 1.2, < 3.0)
sprockets (3.7.2)
sprockets (4.0.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

concurrent-ruby (~> 1.0)
rack (> 1, < 3)
sprockets-es6 (0.9.2)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

sprockets-es6

Gem removed 🔥

[change-log, source-code]

@@ -412,7 +403,7 @@ GEM
net-ssh (>= 2.8.0)
sshkit-interactive (0.3.0)
sshkit (~> 1.12)
thor (0.20.3)
thor (1.0.1)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@@ -424,7 +415,7 @@ GEM
unf_ext
unf_ext (0.0.7.6)
unicode-display_width (1.6.0)
uniform_notifier (1.12.1)
uniform_notifier (1.13.0)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@@ -436,14 +427,14 @@ GEM
addressable (>= 2.3.6)
crack (>= 0.3.2)
hashdiff
webpacker (4.0.7)
webpacker (4.2.2)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

activesupport (>= 4.2)
rack-proxy (>= 0.6.1)
railties (>= 4.2)
websocket-driver (0.7.1)
websocket-extensions (>= 0.1.0)
websocket-extensions (0.1.4)
zeitwerk (2.1.10)
zeitwerk (2.2.2)
Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sobanakram sobanakram merged commit 7422c6f into master Dec 20, 2019
@sobanakram sobanakram deleted the auto_bundle_update_20191220-1654 branch December 20, 2019 12:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant