diff --git a/Changelog.md b/Changelog.md index 879ca4e86b589ab77f15a9e236b7213bf7f6eea6..c552f0b4f7e74d0e1582c57c518ab65c6cd78d39 100644 --- a/Changelog.md +++ b/Changelog.md @@ -1,3 +1,7 @@ +# 0.7.0.1 + +Update nokogiri to fix [multiple libxml2 vulnerabilities](https://usn.ubuntu.com/usn/usn-3424-1/). + # 0.7.0.0 ## Supported Ruby versions diff --git a/Gemfile b/Gemfile index 532d4dd9e1548d410ff11bea906a74c58ac85ca4..c7cc848d9dbf071018fb983f67d3d36417281747 100644 --- a/Gemfile +++ b/Gemfile @@ -135,7 +135,7 @@ gem "leaflet-rails", "1.1.0" # Parsing -gem "nokogiri", "1.8.0" +gem "nokogiri", "1.8.1" gem "open_graph_reader", "0.6.2" # also update User-Agent in features/support/webmock.rb gem "redcarpet", "3.4.0" gem "ruby-oembed", "0.12.0" diff --git a/Gemfile.lock b/Gemfile.lock index 5bc4f2ec5c80f46fe9e96fd3071b7b1cca4644b3..b2365e6224829a495b054f3975dd1c4764177b86 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -374,7 +374,7 @@ GEM mime-types-data (3.2016.0521) mini_magick (4.8.0) mini_mime (0.1.4) - mini_portile2 (2.2.0) + mini_portile2 (2.3.0) minitest (5.10.3) mobile_fu (1.4.0) rack-mobile-detect @@ -387,8 +387,8 @@ GEM naught (1.1.0) nenv (0.3.0) nio4r (2.1.0) - nokogiri (1.8.0) - mini_portile2 (~> 2.2.0) + nokogiri (1.8.1) + mini_portile2 (~> 2.3.0) notiffany (0.1.1) nenv (~> 0.1) shellany (~> 0.0) @@ -820,7 +820,7 @@ DEPENDENCIES minitest mobile_fu (= 1.4.0) mysql2 (= 0.4.9) - nokogiri (= 1.8.0) + nokogiri (= 1.8.1) omniauth (= 1.6.1) omniauth-facebook (= 4.0.0) omniauth-tumblr (= 1.2) @@ -904,4 +904,4 @@ DEPENDENCIES will_paginate (= 3.1.6) BUNDLED WITH - 1.15.3 + 1.15.4 diff --git a/config/defaults.yml b/config/defaults.yml index 2ffaf3fe06185f6335c5e254ef04ed5b73e8891c..2871abf7b7d18ceec85530d57a8b7e7dc0041759 100644 --- a/config/defaults.yml +++ b/config/defaults.yml @@ -4,7 +4,7 @@ defaults: version: - number: "0.7.0.0" # Do not touch unless doing a release, do not backport the version number that's in master + number: "0.7.0.1" # Do not touch unless doing a release, do not backport the version number that's in master heroku: false environment: url: "http://localhost:3000/"