From 154f7b0a81b0e5e973e6a8d0804dfa07113a0285 Mon Sep 17 00:00:00 2001 From: Carlos Eduardo Cabral da Cunha Date: Wed, 20 Mar 2019 11:34:29 -0300 Subject: [PATCH 1/2] #290 updating devise gem from 4.3.0 to 4.6.0 due security vulnerability --- Gemfile | 2 +- Gemfile.lock | 20 ++++++++++---------- 2 files changed, 11 insertions(+), 11 deletions(-) diff --git a/Gemfile b/Gemfile index acb5f005..1eecc3b8 100644 --- a/Gemfile +++ b/Gemfile @@ -44,7 +44,7 @@ gem "kaminari" #gem "schema_plus" gem 'cancancan' -gem "devise" +gem "devise", ">= 4.6.0" gem "paper_trail" gem 'sql-parser' diff --git a/Gemfile.lock b/Gemfile.lock index 572eaec5..ebd0b6a9 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -73,8 +73,8 @@ GEM tzinfo (~> 1.1) arel (8.0.0) awesome_print (1.6.1) - bcrypt (3.1.10) - bcrypt (3.1.10-x86-mingw32) + bcrypt (3.1.12) + bcrypt (3.1.12-x86-mingw32) better_errors (2.1.1) coderay (>= 1.0.0) erubis (>= 2.6.6) @@ -105,10 +105,10 @@ GEM concurrent-ruby (1.1.5) crass (1.0.4) debug_inspector (0.0.2) - devise (4.3.0) + devise (4.6.1) bcrypt (~> 3.0) orm_adapter (~> 0.1) - railties (>= 4.1.0, < 5.2) + railties (>= 4.1.0, < 6.0) responders warden (~> 1.2.3) diff-lcs (1.3) @@ -231,9 +231,9 @@ GEM rails (>= 4.0.0) redcarpet (3.2.2) request_store (1.3.2) - responders (2.4.0) - actionpack (>= 4.2.0, < 5.3) - railties (>= 4.2.0, < 5.3) + responders (2.4.1) + actionpack (>= 4.2.0, < 6.0) + railties (>= 4.2.0, < 6.0) rghost (0.9.6) rspec-collection_matchers (1.1.3) rspec-expectations (>= 2.99.0.beta1) @@ -298,8 +298,8 @@ GEM json (>= 1.8.0) validates_timeliness (3.0.14) timeliness (~> 0.3.6) - warden (1.2.3) - rack (>= 1.0) + warden (1.2.8) + rack (>= 2.0.6) webrick (1.4.2) websocket-driver (0.6.5) websocket-extensions (>= 0.1.0) @@ -325,7 +325,7 @@ DEPENDENCIES clamsy! codemirror-rails coffee-rails - devise + devise (>= 4.6.0) exception_notification (= 2.6.1) factory_girl_rails ffi (>= 1.9.24) From 6f8b402bbc927b7a595f4e2188585d1628149e44 Mon Sep 17 00:00:00 2001 From: Carlos Eduardo Cabral da Cunha Date: Mon, 1 Apr 2019 18:03:45 -0300 Subject: [PATCH 2/2] #290 updating to devise 4.6.2 which reverses an issue which breaks backward compatibility --- Gemfile | 2 +- Gemfile.lock | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/Gemfile b/Gemfile index 1eecc3b8..a742d7a7 100644 --- a/Gemfile +++ b/Gemfile @@ -44,7 +44,7 @@ gem "kaminari" #gem "schema_plus" gem 'cancancan' -gem "devise", ">= 4.6.0" +gem "devise", ">= 4.6.2" gem "paper_trail" gem 'sql-parser' diff --git a/Gemfile.lock b/Gemfile.lock index ebd0b6a9..47519405 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -105,7 +105,7 @@ GEM concurrent-ruby (1.1.5) crass (1.0.4) debug_inspector (0.0.2) - devise (4.6.1) + devise (4.6.2) bcrypt (~> 3.0) orm_adapter (~> 0.1) railties (>= 4.1.0, < 6.0) @@ -325,7 +325,7 @@ DEPENDENCIES clamsy! codemirror-rails coffee-rails - devise (>= 4.6.0) + devise (>= 4.6.2) exception_notification (= 2.6.1) factory_girl_rails ffi (>= 1.9.24)