From 067efa74b4a74e5ec63931991b280787636416d1 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 25 Feb 2020 05:18:38 +0000 Subject: [PATCH] fix: Gemfile & Gemfile.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-RUBY-RAKE-552000 --- Gemfile | 4 ++-- Gemfile.lock | 60 +++++++++++++++++++++++++++------------------------- 2 files changed, 33 insertions(+), 31 deletions(-) diff --git a/Gemfile b/Gemfile index c3b3c053..8fbfc509 100644 --- a/Gemfile +++ b/Gemfile @@ -21,9 +21,9 @@ gem 'ruby-augeas', rbaugversion group :development do gem 'puppet-lint' - gem 'puppet-syntax' + gem 'puppet-syntax', '>= 1.1.0' gem 'puppetlabs_spec_helper', '>= 0.4.1' - gem 'rake' + gem 'rake', '>= 12.3.3' gem 'rspec-puppet', :git => 'https://github.com/rodjek/rspec-puppet.git', :ref => '544b168' gem 'simplecov' gem 'yard' diff --git a/Gemfile.lock b/Gemfile.lock index 19f849c3..c2de53f4 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -38,9 +38,10 @@ GEM thor builder (3.2.2) coderay (1.0.9) - diff-lcs (1.2.4) + diff-lcs (1.3) excon (0.31.0) - facter (1.7.5) + facter (2.5.7) + fast_gettext (1.1.2) fission (0.5.0) CFPropertyList (~> 2.2) fog (1.19.0) @@ -54,18 +55,15 @@ GEM nokogiri (~> 1.5) ruby-hmac formatador (0.2.4) - hiera (1.3.2) - json_pure + hiera (3.6.0) highline (1.6.21) inifile (2.0.2) json (1.8.1) - json_pure (1.8.1) - metaclass (0.0.1) + locale (2.1.3) method_source (0.8.2) mime-types (1.25.1) minitar (0.5.4) - mocha (0.14.0) - metaclass (~> 0.0.1) + mocha (1.11.2) multi_json (1.8.1) net-scp (1.1.2) net-ssh (>= 2.6.5) @@ -75,34 +73,35 @@ GEM coderay (~> 1.0.5) method_source (~> 0.8) slop (~> 3.4) - puppet (3.4.3) - facter (~> 1.6) - hiera (~> 1.0) - rgen (~> 0.6.5) + puppet (5.4.0) + facter (> 2.0.1, < 4) + fast_gettext (~> 1.1.2) + hiera (>= 3.2.1, < 4) + locale (~> 2.1) puppet-lint (0.3.2) - puppet-syntax (1.1.0) - puppet (>= 2.7.0) + puppet-syntax (2.6.1) + puppet (>= 5) rake - puppetlabs_spec_helper (0.4.1) - mocha (>= 0.10.5) + puppetlabs_spec_helper (1.1.1) + mocha + puppet-lint + puppet-syntax rake - rspec (>= 2.9.0) - rspec-puppet (>= 0.1.1) - rake (10.1.0) + rspec-puppet + rake (13.0.1) rbvmomi (1.8.1) builder nokogiri (>= 1.4.1) trollop redcarpet (2.3.0) - rgen (0.6.6) - rspec (2.14.1) - rspec-core (~> 2.14.0) - rspec-expectations (~> 2.14.0) - rspec-mocks (~> 2.14.0) - rspec-core (2.14.5) - rspec-expectations (2.14.3) + rspec (2.99.0) + rspec-core (~> 2.99.0) + rspec-expectations (~> 2.99.0) + rspec-mocks (~> 2.99.0) + rspec-core (2.99.2) + rspec-expectations (2.99.2) diff-lcs (>= 1.1.3, < 2.0) - rspec-mocks (2.14.3) + rspec-mocks (2.99.4) ruby-augeas (0.5.0) ruby-hmac (0.4.0) serverspec (0.15.4) @@ -133,12 +132,15 @@ DEPENDENCIES pry puppet (>= 2.7) puppet-lint - puppet-syntax + puppet-syntax (>= 1.1.0) puppetlabs_spec_helper (>= 0.4.1) - rake + rake (>= 12.3.3) redcarpet (~> 2.0) rspec-puppet! ruby-augeas (~> 0.3) simplecov vagrant-wrapper yard + +BUNDLED WITH + 1.17.3