@@ -4,27 +4,24 @@ source ENV['GEM_SOURCE'] || 'https://rubygems.org'
44
55gem 'facter' , ENV [ 'RUBYGEM_FACTER' ]
66gem 'modulesync' , ENV [ 'RUBYGEM_MODULESYNC' ]
7- gem 'puppet ' , ENV [ 'RUBYGEM_PUPPET ' ]
7+ gem 'onceover ' , ENV [ 'RUBYGEM_ONCEOVER ' ]
88gem 'puppet_metadata' , ENV [ 'RUBYGEM_PUPPET_METADATA' ]
9+ gem 'puppet-ghostbuster' , ENV [ 'RUBYGEM_PUPPET_GHOSTBUSTER' ]
10+ gem 'puppet' , ENV [ 'RUBYGEM_PUPPET' ]
911gem 'r10k' , ENV [ 'RUBYGEM_R10K' ]
1012gem 'ra10ke' , ENV [ 'RUBYGEM_RA10KE' ]
13+ gem 'rspec_junit_formatter' , ENV [ 'RUBYGEM_RSPEC_JUNIT_FORMATTER' ]
14+ gem 'rubocop-performance' , ENV [ 'RUBYGEM_RUBOCOP_PERFORMANCE' ]
1115gem 'voxpupuli-acceptance' , ENV [ 'RUBYGEM_VOXPUPULI_ACCEPTANCE' ]
1216gem 'voxpupuli-release' , ENV [ 'RUBYGEM_VOXPUPULI_RELEASE' ]
1317gem 'voxpupuli-test' , ENV [ 'RUBYGEM_VOXPUPULI_TEST' ]
14- gem 'rubocop-performance' , ENV [ 'RUBYGEM_RUBOCOP_PERFORMANCE' ]
15- gem 'onceover' , ENV [ 'RUBYGEM_ONCEOVER' ]
16- gem 'rspec_junit_formatter' , ENV [ 'RUBYGEM_RSPEC_JUNIT_FORMATTER' ]
17- gem 'puppet-ghostbuster' , ENV [ 'RUBYGEM_PUPPET_GHOSTBUSTER' ]
1818
1919# CVE fixes
20- gem 'cgi' , '~> 0.4.1' # cgi 0.1.0 has CVEs - remove default and install upstream replacement
21- gem 'stringio' , '~> 3.1' # stringio 0.1.0 has CVEs - remove default and install upstream replacement
22- gem 'rexml' , '~> 3.3' , '>= 3.3.6' # rexml < 3.3 has CVEs - remove default and install upstream replacement
23- gem 'rdoc' , '~> 6.7' # rdoc 6.2.1 has CVEs - remove default and install upstream replacement
24-
25- # Pin dependencies to avoid installing duplicate versions
26- # see https://github.com/voxpupuli/container-voxbox/issues/97
27- gem 'racc' , '1.8.1'
28- gem 'minitest' , '5.16.3'
29- gem 'drb' , '2.1.1'
30- gem 'csv' , '3.2.6'
20+ gem 'cgi' , '~> 0.5' # cgi 0.1.0 has CVEs - remove default and install upstream replacement
21+ gem 'csv' , '~> 3.2' # csv 3.1.2 has CVEs - remove default and install upstream replacement
22+ gem 'drb' , '~> 2.2' # drb 2.1.1 has CVEs - remove default and install upstream replacement
23+ gem 'minitest' , '~> 5.25' # minitest 5.16.3 has CVEs - remove default and install upstream replacement
24+ gem 'racc' , '~> 1.8' # racc 1.6.2 has CVEs - remove default and install upstream replacement
25+ gem 'rdoc' , '~> 6.14' # rdoc 6.2.1 has CVEs - remove default and install upstream replacement
26+ gem 'rexml' , '~> 3.4' # rexml < 3.3 has CVEs - remove default and install upstream replacement
27+ gem 'stringio' , '~> 3.1' # stringio 0.1.0 has CVEs - remove default and install upstream replacement
0 commit comments