Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Gems #42

Merged
merged 1 commit into from
Mar 12, 2019
Merged

Update Gems #42

merged 1 commit into from
Mar 12, 2019

Conversation

ramu
Copy link
Contributor

@ramu ramu commented Mar 12, 2019

目的

1 nokogiri vulnerability found in Gemfile.lock on 18 Jan
Remediation
Upgrade nokogiri to version 1.8.5 or later. For example:

gem "nokogiri", ">= 1.8.5"
Always verify the validity and compatibility of suggestions with your codebase.

上記指摘あり。Gemfile.lockの更新を行う。

@ramu ramu self-assigned this Mar 12, 2019
@ramu ramu force-pushed the fix/update-nokogiri-version branch from 7f01302 to 8859e84 Compare March 12, 2019 12:33
@ramu ramu changed the title [WIP] Update nokogiri version [WIP] Update Gems Mar 12, 2019
@ramu ramu changed the title [WIP] Update Gems Update Gems Mar 12, 2019
@ramu ramu requested a review from kkd March 12, 2019 12:51
@kazweda kazweda merged commit d80838f into master Mar 12, 2019
@kazweda
Copy link
Contributor

kazweda commented Mar 12, 2019

手元のフォーク先で bundle update したら同じ状態になったのでマージしました。
あと、ローカル環境で bundle を実行すると

The dependency tzinfo-data (>= 0) will be unused by any of the platforms Bundler
is installing for. Bundler is installing for ruby but the dependency is only for x86-mingw32,
x86-mswin32, x64-mingw32, java. To add those platforms to the bundle,
run bundle lock --add-platform x86-mingw32 x86-mswin32 x64-mingw32 java.

というメッセージが出たので、
https://pcl.solima.net/ror5/archives/21
この記事を参考に調整中です。
他に気がついたこともあるので、合わせて別途対応します。

@ramu ramu deleted the fix/update-nokogiri-version branch March 12, 2019 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants