From da077e500abe1d57187bbf8c06413b59412ce531 Mon Sep 17 00:00:00 2001 From: Ariel Shin <59939028+ashin-omg@users.noreply.github.com> Date: Tue, 5 Jan 2021 11:02:18 -0800 Subject: [PATCH] Update nokogiri Nokogiri < 1.11 is vulnerable to XML External Entity (XXE) Injection https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-1055008 --- slather.gemspec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/slather.gemspec b/slather.gemspec index 12ab20d3..4ff523da 100644 --- a/slather.gemspec +++ b/slather.gemspec @@ -29,7 +29,7 @@ Gem::Specification.new do |spec| spec.add_dependency 'clamp', '~> 1.3' spec.add_dependency 'xcodeproj', '~> 1.7' - spec.add_dependency 'nokogiri', '~> 1.8' + spec.add_dependency 'nokogiri', '~> 1.11' spec.add_dependency 'CFPropertyList', '>= 2.2', '< 4' spec.add_runtime_dependency 'activesupport'