Updated rails to 5.2.4.2 (CVE-2020-5267) and json (CVE-2020-10663).

This commit is contained in:
Martin Edenhofer 2020-03-19 23:19:19 +01:00
parent becbdb1baa
commit 1061803fba
2 changed files with 46 additions and 46 deletions

View file

@ -2,7 +2,7 @@ source 'https://rubygems.org'
# core - base # core - base
ruby '2.6.5' ruby '2.6.5'
gem 'rails', '5.2.4.1' gem 'rails', '5.2.4.2'
# core - rails additions # core - rails additions
gem 'activerecord-import' gem 'activerecord-import'

View file

@ -49,37 +49,37 @@ GEM
specs: specs:
aasm (5.0.0) aasm (5.0.0)
concurrent-ruby (~> 1.0) concurrent-ruby (~> 1.0)
actioncable (5.2.4.1) actioncable (5.2.4.2)
actionpack (= 5.2.4.1) actionpack (= 5.2.4.2)
nio4r (~> 2.0) nio4r (~> 2.0)
websocket-driver (>= 0.6.1) websocket-driver (>= 0.6.1)
actionmailer (5.2.4.1) actionmailer (5.2.4.2)
actionpack (= 5.2.4.1) actionpack (= 5.2.4.2)
actionview (= 5.2.4.1) actionview (= 5.2.4.2)
activejob (= 5.2.4.1) activejob (= 5.2.4.2)
mail (~> 2.5, >= 2.5.4) mail (~> 2.5, >= 2.5.4)
rails-dom-testing (~> 2.0) rails-dom-testing (~> 2.0)
actionpack (5.2.4.1) actionpack (5.2.4.2)
actionview (= 5.2.4.1) actionview (= 5.2.4.2)
activesupport (= 5.2.4.1) activesupport (= 5.2.4.2)
rack (~> 2.0, >= 2.0.8) rack (~> 2.0, >= 2.0.8)
rack-test (>= 0.6.3) rack-test (>= 0.6.3)
rails-dom-testing (~> 2.0) rails-dom-testing (~> 2.0)
rails-html-sanitizer (~> 1.0, >= 1.0.2) rails-html-sanitizer (~> 1.0, >= 1.0.2)
actionview (5.2.4.1) actionview (5.2.4.2)
activesupport (= 5.2.4.1) activesupport (= 5.2.4.2)
builder (~> 3.1) builder (~> 3.1)
erubi (~> 1.4) erubi (~> 1.4)
rails-dom-testing (~> 2.0) rails-dom-testing (~> 2.0)
rails-html-sanitizer (~> 1.0, >= 1.0.3) rails-html-sanitizer (~> 1.0, >= 1.0.3)
activejob (5.2.4.1) activejob (5.2.4.2)
activesupport (= 5.2.4.1) activesupport (= 5.2.4.2)
globalid (>= 0.3.6) globalid (>= 0.3.6)
activemodel (5.2.4.1) activemodel (5.2.4.2)
activesupport (= 5.2.4.1) activesupport (= 5.2.4.2)
activerecord (5.2.4.1) activerecord (5.2.4.2)
activemodel (= 5.2.4.1) activemodel (= 5.2.4.2)
activesupport (= 5.2.4.1) activesupport (= 5.2.4.2)
arel (>= 9.0) arel (>= 9.0)
activerecord-import (1.0.2) activerecord-import (1.0.2)
activerecord (>= 3.2) activerecord (>= 3.2)
@ -91,11 +91,11 @@ GEM
multi_json (~> 1.11, >= 1.11.2) multi_json (~> 1.11, >= 1.11.2)
rack (>= 1.5.2, < 3) rack (>= 1.5.2, < 3)
railties (>= 4.0) railties (>= 4.0)
activestorage (5.2.4.1) activestorage (5.2.4.2)
actionpack (= 5.2.4.1) actionpack (= 5.2.4.2)
activerecord (= 5.2.4.1) activerecord (= 5.2.4.2)
marcel (~> 0.3.1) marcel (~> 0.3.1)
activesupport (5.2.4.1) activesupport (5.2.4.2)
concurrent-ruby (~> 1.0, >= 1.0.2) concurrent-ruby (~> 1.0, >= 1.0.2)
i18n (>= 0.7, < 2) i18n (>= 0.7, < 2)
minitest (~> 5.1) minitest (~> 5.1)
@ -149,7 +149,7 @@ GEM
json json
composite_primary_keys (11.2.0) composite_primary_keys (11.2.0)
activerecord (~> 5.2.1) activerecord (~> 5.2.1)
concurrent-ruby (1.1.5) concurrent-ruby (1.1.6)
coveralls (0.8.23) coveralls (0.8.23)
json (>= 1.8, < 3) json (>= 1.8, < 3)
simplecov (~> 0.16.1) simplecov (~> 0.16.1)
@ -158,7 +158,7 @@ GEM
tins (~> 1.6) tins (~> 1.6)
crack (0.4.3) crack (0.4.3)
safe_yaml (~> 1.0.0) safe_yaml (~> 1.0.0)
crass (1.0.5) crass (1.0.6)
daemons (1.3.1) daemons (1.3.1)
dalli (2.7.10) dalli (2.7.10)
debug_inspector (0.0.3) debug_inspector (0.0.3)
@ -245,7 +245,7 @@ GEM
http-form_data (2.1.1) http-form_data (2.1.1)
http_parser.rb (0.6.0) http_parser.rb (0.6.0)
httpclient (2.8.3) httpclient (2.8.3)
i18n (1.7.0) i18n (1.8.2)
concurrent-ruby (~> 1.0) concurrent-ruby (~> 1.0)
icalendar (2.5.3) icalendar (2.5.3)
ice_cube (~> 0.16) ice_cube (~> 0.16)
@ -256,7 +256,7 @@ GEM
inflection (1.0.0) inflection (1.0.0)
interception (0.5) interception (0.5)
jaro_winkler (1.5.4) jaro_winkler (1.5.4)
json (2.2.0) json (2.3.0)
jwt (2.2.1) jwt (2.2.1)
kgio (2.11.2) kgio (2.11.2)
koala (3.0.0) koala (3.0.0)
@ -284,12 +284,12 @@ GEM
mime-types (3.2.2) mime-types (3.2.2)
mime-types-data (~> 3.2015) mime-types-data (~> 3.2015)
mime-types-data (3.2019.0331) mime-types-data (3.2019.0331)
mimemagic (0.3.3) mimemagic (0.3.4)
mini_mime (1.0.2) mini_mime (1.0.2)
mini_portile2 (2.4.0) mini_portile2 (2.4.0)
mini_racer (0.2.9) mini_racer (0.2.9)
libv8 (>= 6.9.411) libv8 (>= 6.9.411)
minitest (5.13.0) minitest (5.14.0)
msgpack (1.2.4) msgpack (1.2.4)
multi_json (1.14.1) multi_json (1.14.1)
multi_xml (0.6.0) multi_xml (0.6.0)
@ -301,7 +301,7 @@ GEM
net-ldap (0.16.1) net-ldap (0.16.1)
netrc (0.11.0) netrc (0.11.0)
nio4r (2.5.2) nio4r (2.5.2)
nokogiri (1.10.8) nokogiri (1.10.9)
mini_portile2 (~> 2.4.0) mini_portile2 (~> 2.4.0)
nori (2.6.0) nori (2.6.0)
notiffany (0.1.1) notiffany (0.1.1)
@ -387,18 +387,18 @@ GEM
rack rack
rack-test (1.1.0) rack-test (1.1.0)
rack (>= 1.0, < 3) rack (>= 1.0, < 3)
rails (5.2.4.1) rails (5.2.4.2)
actioncable (= 5.2.4.1) actioncable (= 5.2.4.2)
actionmailer (= 5.2.4.1) actionmailer (= 5.2.4.2)
actionpack (= 5.2.4.1) actionpack (= 5.2.4.2)
actionview (= 5.2.4.1) actionview (= 5.2.4.2)
activejob (= 5.2.4.1) activejob (= 5.2.4.2)
activemodel (= 5.2.4.1) activemodel (= 5.2.4.2)
activerecord (= 5.2.4.1) activerecord (= 5.2.4.2)
activestorage (= 5.2.4.1) activestorage (= 5.2.4.2)
activesupport (= 5.2.4.1) activesupport (= 5.2.4.2)
bundler (>= 1.3.0) bundler (>= 1.3.0)
railties (= 5.2.4.1) railties (= 5.2.4.2)
sprockets-rails (>= 2.0.0) sprockets-rails (>= 2.0.0)
rails-controller-testing (1.0.4) rails-controller-testing (1.0.4)
actionpack (>= 5.0.1.x) actionpack (>= 5.0.1.x)
@ -411,9 +411,9 @@ GEM
loofah (~> 2.3) loofah (~> 2.3)
rails-observers (0.1.5) rails-observers (0.1.5)
activemodel (>= 4.0) activemodel (>= 4.0)
railties (5.2.4.1) railties (5.2.4.2)
actionpack (= 5.2.4.1) actionpack (= 5.2.4.2)
activesupport (= 5.2.4.1) activesupport (= 5.2.4.2)
method_source method_source
rake (>= 0.8.7) rake (>= 0.8.7)
thor (>= 0.19.0, < 2.0) thor (>= 0.19.0, < 2.0)
@ -525,7 +525,7 @@ GEM
faraday (~> 0.9) faraday (~> 0.9)
jwt (>= 1.5, <= 2.5) jwt (>= 1.5, <= 2.5)
nokogiri (>= 1.6, < 2.0) nokogiri (>= 1.6, < 2.0)
tzinfo (1.2.5) tzinfo (1.2.6)
thread_safe (~> 0.1) thread_safe (~> 0.1)
uglifier (4.1.20) uglifier (4.1.20)
execjs (>= 0.3.0, < 3) execjs (>= 0.3.0, < 3)
@ -634,7 +634,7 @@ DEPENDENCIES
pundit pundit
pundit-matchers pundit-matchers
rack-livereload rack-livereload
rails (= 5.2.4.1) rails (= 5.2.4.2)
rails-controller-testing rails-controller-testing
rails-observers rails-observers
rb-fsevent rb-fsevent