Skip to content

Commit 1b1f2ee

Browse files
author
Kazuyoshi Kato
authored
fix: upgrade sinatra to clear GHSA-hxx2-7vcw-mqr3 (#4582)
We are not affected, but it is better to clear the Dependabot alert. GHSA-hxx2-7vcw-mqr3
1 parent c7bac9a commit 1b1f2ee

File tree

2 files changed

+19
-10
lines changed

2 files changed

+19
-10
lines changed

test/preflight/fixtures/example-buildpack/Gemfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,4 +11,4 @@ gem "rack"
1111
# https://bugs.ruby-lang.org/issues/17303
1212
gem "puma"
1313

14-
gem "sinatra"
14+
gem "sinatra", "~> 4.1"
Lines changed: 18 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,19 +1,28 @@
11
GEM
22
remote: https://rubygems.org/
33
specs:
4-
mustermann (2.0.2)
4+
base64 (0.3.0)
5+
logger (1.7.0)
6+
mustermann (3.0.4)
57
ruby2_keywords (~> 0.0.1)
68
nio4r (2.7.4)
79
puma (6.5.0)
810
nio4r (~> 2.0)
9-
rack (2.2.18)
10-
rack-protection (2.2.3)
11-
rack
11+
rack (3.2.1)
12+
rack-protection (4.1.1)
13+
base64 (>= 0.1.0)
14+
logger (>= 1.6.0)
15+
rack (>= 3.0.0, < 4)
16+
rack-session (2.1.1)
17+
base64 (>= 0.1.0)
18+
rack (>= 3.0.0)
1219
ruby2_keywords (0.0.5)
13-
sinatra (2.2.3)
14-
mustermann (~> 2.0)
15-
rack (~> 2.2)
16-
rack-protection (= 2.2.3)
20+
sinatra (4.1.1)
21+
logger (>= 1.6.0)
22+
mustermann (~> 3.0)
23+
rack (>= 3.0.0, < 4)
24+
rack-protection (= 4.1.1)
25+
rack-session (>= 2.0.0, < 3)
1726
tilt (~> 2.0)
1827
tilt (2.1.0)
1928

@@ -23,7 +32,7 @@ PLATFORMS
2332
DEPENDENCIES
2433
puma
2534
rack
26-
sinatra
35+
sinatra (~> 4.1)
2736

2837
BUNDLED WITH
2938
2.6.1

0 commit comments

Comments
 (0)