From f053d23bba75c71ee1467e432a628e6ba44e91b4 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 20 Jul 2020 06:03:38 +0000 Subject: [PATCH] fix: Gemfile & Gemfile.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-KRAMDOWN-585939 --- Gemfile | 2 +- Gemfile.lock | 25 ++++++++++++++++--------- 2 files changed, 17 insertions(+), 10 deletions(-) diff --git a/Gemfile b/Gemfile index e274141e0..89cfbde97 100644 --- a/Gemfile +++ b/Gemfile @@ -1,4 +1,4 @@ # frozen_string_literal: true source "https://rubygems.org" -gem 'mdl', '0.4.0' +gem 'mdl', '0.7.0' diff --git a/Gemfile.lock b/Gemfile.lock index 9fa9442ba..602dba0ff 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -1,19 +1,26 @@ GEM remote: https://rubygems.org/ specs: - kramdown (1.13.2) - mdl (0.4.0) - kramdown (~> 1.12, >= 1.12.0) - mixlib-cli (~> 1.7, >= 1.7.0) - mixlib-config (~> 2.2, >= 2.2.1) - mixlib-cli (1.7.0) - mixlib-config (2.2.4) + kramdown (2.3.0) + rexml + kramdown-parser-gfm (1.1.0) + kramdown (~> 2.0) + mdl (0.7.0) + kramdown (~> 2.0) + kramdown-parser-gfm (~> 1.0) + mixlib-cli (~> 2.1, >= 2.1.1) + mixlib-config (>= 2.2.1, < 4) + mixlib-cli (2.1.6) + mixlib-config (3.0.6) + tomlrb + rexml (3.2.4) + tomlrb (1.3.0) PLATFORMS ruby DEPENDENCIES - mdl (= 0.4.0) + mdl (= 0.7.0) BUNDLED WITH - 1.14.6 + 1.17.3