Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[Snyk] Security upgrade rspec-rails from 3.5.2 to 8.0.0 #129

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
enterstudio wants to merge 1 commit into master
base: master
Choose a base branch
Loading
from snyk-fix-c3391cb78c40ad21056ec463146521a8

Conversation

@enterstudio
Copy link
Owner

@enterstudio enterstudio commented May 7, 2025

snyk-top-banner

Snyk has created this PR to fix 18 vulnerabilities in the rubygems dependencies of this project.

Snyk changed the following file(s):

  • Gemfile
⚠️ Warning
Failed to update the Gemfile.lock, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity Arbitrary Code Injection
SNYK-RUBY-RACK-2848599
704
medium severity Cross-site Request Forgery (CSRF)
SNYK-RUBY-RACK-572377
646
medium severity Cross-site Scripting (XSS)
SNYK-RUBY-RAILSHTMLSANITIZER-3168647
626
medium severity Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONVIEW-2803851
591
high severity Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-LOOFAH-3168317
589
high severity Denial of Service (DoS)
SNYK-RUBY-RACK-2848600
589
high severity Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-RAILSHTMLSANITIZER-3168646
589
high severity Information Exposure
SNYK-RUBY-ACTIONPACK-2400638
584
high severity Cross-site Scripting (XSS)
SNYK-RUBY-LOOFAH-474102
579
medium severity Cross-site Scripting (XSS)
SNYK-RUBY-RAILSHTMLSANITIZER-2935879
531
medium severity Cross-site Scripting (XSS)
SNYK-RUBY-ACTIVESUPPORT-3360028
519
medium severity Cross-site Scripting (XSS)
SNYK-RUBY-LOOFAH-72548
484
medium severity Cross-site Scripting (XSS)
SNYK-RUBY-RAILSHTMLSANITIZER-3168316
484
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIONPACK-3237231
479
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIONPACK-3237232
479
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIVESUPPORT-3237242
479
medium severity Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-5741907
449
medium severity Cross-site Scripting (XSS)
SNYK-RUBY-RAILSHTMLSANITIZER-3168648
424

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Cross-site Scripting (XSS)
🦉 Cross-site Scripting (XSS)
🦉 More lessons are available in Snyk Learn

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-RUBY-RACK-2848599
- https://snyk.io/vuln/SNYK-RUBY-RACK-572377
- https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168647
- https://snyk.io/vuln/SNYK-RUBY-ACTIONVIEW-2803851
- https://snyk.io/vuln/SNYK-RUBY-LOOFAH-3168317
- https://snyk.io/vuln/SNYK-RUBY-RACK-2848600
- https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168646
- https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-2400638
- https://snyk.io/vuln/SNYK-RUBY-LOOFAH-474102
- https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-2935879
- https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-3360028
- https://snyk.io/vuln/SNYK-RUBY-LOOFAH-72548
- https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168316
- https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-3237231
- https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-3237232
- https://snyk.io/vuln/SNYK-RUBY-ACTIVESUPPORT-3237242
- https://snyk.io/vuln/SNYK-RUBY-ACTIONPACK-5741907
- https://snyk.io/vuln/SNYK-RUBY-RAILSHTMLSANITIZER-3168648 
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

AltStyle によって変換されたページ (->オリジナル) /