From 1157c444750b70cedd3a8fe6eb389105e63a0575 Mon Sep 17 00:00:00 2001 From: Brandon Medenwald Date: Tue, 16 Jul 2024 14:00:43 -0500 Subject: [PATCH 1/2] Update rexml dependency to 3.3.2 for CVE-2024-39908 --- Gemfile.lock | 6 ++++-- xcodeproj.gemspec | 2 +- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index efb4d95f..9e61f54c 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -20,7 +20,7 @@ PATH claide (>= 1.0.2, < 2.0) colored2 (~> 3.1) nanaimo (~> 0.3.0) - rexml (~> 3.2.4) + rexml (~> 3.3.2) GEM remote: https://rubygems.org/ @@ -94,7 +94,8 @@ GEM ffi (>= 0.5.0) rb-kqueue (0.2.4) ffi (>= 0.5.0) - rexml (3.2.6) + rexml (3.3.2) + strscan rubocop (0.47.1) parser (>= 2.3.3.1, < 3.0) powerpack (~> 0.1) @@ -110,6 +111,7 @@ GEM multi_json (~> 1.0) simplecov-html (~> 0.9.0) simplecov-html (0.9.0) + strscan (3.1.0) terminal-table (1.8.0) unicode-display_width (~> 1.1, >= 1.1.1) unicode-display_width (1.4.0) diff --git a/xcodeproj.gemspec b/xcodeproj.gemspec index cf76e220..64830415 100644 --- a/xcodeproj.gemspec +++ b/xcodeproj.gemspec @@ -26,7 +26,7 @@ Gem::Specification.new do |s| s.add_runtime_dependency 'claide', '>= 1.0.2', '< 2.0' s.add_runtime_dependency 'colored2', '~> 3.1' s.add_runtime_dependency 'nanaimo', '~> 0.3.0' - s.add_runtime_dependency 'rexml', '~> 3.2.4' + s.add_runtime_dependency 'rexml', '~> 3.3.2' ## Make sure you can build the gem on older versions of RubyGems too: s.rubygems_version = '1.6.2' From 844d4e830d4ceba4682ffde910a17ece9036bae6 Mon Sep 17 00:00:00 2001 From: Brandon Medenwald Date: Wed, 17 Jul 2024 18:26:34 -0500 Subject: [PATCH 2/2] Loosen rexml dependency --- Gemfile.lock | 2 +- xcodeproj.gemspec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index 9e61f54c..1b35d96b 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -20,7 +20,7 @@ PATH claide (>= 1.0.2, < 2.0) colored2 (~> 3.1) nanaimo (~> 0.3.0) - rexml (~> 3.3.2) + rexml (>= 3.3.2, < 4.0) GEM remote: https://rubygems.org/ diff --git a/xcodeproj.gemspec b/xcodeproj.gemspec index 64830415..15fa248c 100644 --- a/xcodeproj.gemspec +++ b/xcodeproj.gemspec @@ -26,7 +26,7 @@ Gem::Specification.new do |s| s.add_runtime_dependency 'claide', '>= 1.0.2', '< 2.0' s.add_runtime_dependency 'colored2', '~> 3.1' s.add_runtime_dependency 'nanaimo', '~> 0.3.0' - s.add_runtime_dependency 'rexml', '~> 3.3.2' + s.add_runtime_dependency 'rexml', '>= 3.3.2', '< 4.0' ## Make sure you can build the gem on older versions of RubyGems too: s.rubygems_version = '1.6.2'