From 445416c2b43078c9c826718e4176cea7a0030485 Mon Sep 17 00:00:00 2001 From: sinsoku Date: Sun, 1 Dec 2019 01:39:13 +0900 Subject: [PATCH 1/2] Update Nokogiri version for CVE-2019-5477 refs: https://github.com/sparklemotion/nokogiri/issues/1915 --- wovnrb.gemspec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/wovnrb.gemspec b/wovnrb.gemspec index 6752aa81..ceddba82 100644 --- a/wovnrb.gemspec +++ b/wovnrb.gemspec @@ -22,7 +22,7 @@ Gem::Specification.new do |spec| spec.add_dependency 'activesupport' spec.add_dependency 'addressable' spec.add_dependency 'lz4-ruby' - spec.add_dependency 'nokogiri', '~> 1.8.1' + spec.add_dependency 'nokogiri', '>= 1.10.4' spec.add_dependency 'nokogumbo', '>= 1.4.0', '< 2.0.0' spec.add_dependency 'rack' From b2fe87fdf4de70f1ea518d37763ee49003ce467b Mon Sep 17 00:00:00 2001 From: sinsoku Date: Sun, 1 Dec 2019 02:12:49 +0900 Subject: [PATCH 2/2] Fix build errors in Ruby 2.1 and 2.2 --- wovnrb.gemspec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/wovnrb.gemspec b/wovnrb.gemspec index ceddba82..f0a4a5c9 100644 --- a/wovnrb.gemspec +++ b/wovnrb.gemspec @@ -22,7 +22,7 @@ Gem::Specification.new do |spec| spec.add_dependency 'activesupport' spec.add_dependency 'addressable' spec.add_dependency 'lz4-ruby' - spec.add_dependency 'nokogiri', '>= 1.10.4' + spec.add_dependency 'nokogiri', '>= 1.8.1' spec.add_dependency 'nokogumbo', '>= 1.4.0', '< 2.0.0' spec.add_dependency 'rack'