From d070412168102955e822ba25846056a33f2c5368 Mon Sep 17 00:00:00 2001 From: Victor Koronen Date: Tue, 20 Mar 2018 21:40:52 +0100 Subject: [PATCH] Bump nokogiri to address CVE-2017-15412 As reported by `bundler-audit`: > Name: nokogiri > Version: 1.8.1 > Advisory: CVE-2017-15412 > Criticality: Unknown > URL: https://github.com/sparklemotion/nokogiri/issues/1714 > Title: Nokogiri gem, via libxml, is affected by DoS vulnerabilities > Solution: upgrade to >= 1.8.2 --- Gemfile.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Gemfile.lock b/Gemfile.lock index 8b3bcf184..840f1b430 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -76,7 +76,7 @@ GEM minitest (5.8.4) multi_json (1.12.1) multipart-post (2.0.0) - nokogiri (1.8.1) + nokogiri (1.8.2) mini_portile2 (~> 2.3.0) parser (2.3.0.6) ast (~> 2.2)