11source 'https://rubygems.org'
22
33#ruby '2.2.2'
4+ #ruby '2.3.2'
45ruby '2.4.2'
56
67# Bundle edge Rails instead: gem 'rails', github: 'rails/rails'
@@ -27,7 +28,9 @@ gem 'will_paginate', '~> 3.0.6'
2728gem 'bootstrap-will_paginate'
2829
2930# Authentication gem
30- gem 'devise'
31+ # gem 'devise'
32+ gem 'devise' , '4.7.1' # This version is known to have vulnerabilities
33+
3134
3235# I18n gem
3336gem 'rails-i18n'
@@ -56,7 +59,9 @@ gem 'sdoc', '~> 0.4.0', group: :doc
5659gem 'prawn'
5760gem 'prawn-table'
5861gem 'rollbar'
59- gem 'loofah' , '2.2.2' # This version is known to have vulnerabilities
62+ # gem 'loofah', '2.2.2' # This version is known to have vulnerabilities
63+ gem 'nokogiri' , '1.10.10' # This version is known to have vulnerabilities
64+
6065
6166group :development , :test do
6267 # Call 'byebug' anywhere in the code to stop execution and get a debugger console
@@ -71,7 +76,7 @@ group :development, :test do
7176 gem 'factory_girl_rails'
7277 gem "better_errors"
7378 gem "binding_of_caller"
74- gem 'json' , '2.2.9 ' # This version is known to have vulnerabilities
79+ gem 'json' , '1.8.6 ' # This version is known to have vulnerabilities
7580end
7681
7782group :test do
8691group :development do
8792 # Access an IRB console on exception pages or by using <%= console %> in views
8893 gem 'web-console' , '~> 2.0'
89- gem 'rack' , '2.2.3 ' # This version is known to have vulnerabilities
94+ gem 'rack' , '1.6.13 ' # This version is known to have vulnerabilities
9095end
9196
9297group :production do
0 commit comments