From 99b78b3c9a1c9c69779a634e0a2b5b28f414ef92 Mon Sep 17 00:00:00 2001 From: Beth Skurrie Date: Tue, 16 Jun 2020 09:10:24 +1000 Subject: [PATCH] fix: upgrade Rack for vulnerability CVE-2020-8184 --- pact_broker.gemspec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pact_broker.gemspec b/pact_broker.gemspec index d113dc051..41070c2dc 100644 --- a/pact_broker.gemspec +++ b/pact_broker.gemspec @@ -51,7 +51,7 @@ Gem::Specification.new do |gem| gem.add_runtime_dependency 'sequel', '~> 5.28' gem.add_runtime_dependency 'webmachine', '1.5.0' gem.add_runtime_dependency 'semver2', '~> 3.4.2' - gem.add_runtime_dependency 'rack', '~> 2.2' + gem.add_runtime_dependency 'rack', '~> 2.2', '>= 2.2.3' gem.add_runtime_dependency 'redcarpet', '>=3.3.2', '~>3.3' gem.add_runtime_dependency 'pact-support', '~> 1.14', '>= 1.14.1' gem.add_runtime_dependency 'padrino-core', '>= 0.14.3', '~> 0.14'