Skip to content

Commit 708018d

Browse files
committed
Upgrade rack dependency.
1 parent 204ab82 commit 708018d

File tree

3 files changed

+7
-5
lines changed

3 files changed

+7
-5
lines changed

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ version released to date for the Jekyll Heroku Starter Kit.
77

88
- [#bugfix](#bugfix)
99
- Fixed OS Command Injection in Rake [CVE-2020-8130](https://github.com/advisories/GHSA-jppv-gw3r-w3q8).
10+
- Fixed Directory traversal in Rack::Directory app bundled with Rack [CVE-2020-8161](https://github.com/advisories/GHSA-5f9h-9pjv-v6j7).
1011
- Fixed Percent-encoded cookies can be used to overwrite existing prefixed cookie names [CVE-2020-8184](https://github.com/advisories/GHSA-j6w9-fv6q-3q52).
1112
- [#enhancement](#enhancement)
1213
- Updated `jekyll` to `3.7.8`.

Gemfile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@ source 'https://rubygems.org'
22
ruby '2.6.3'
33
gem 'bundler', '1.17.2'
44
gem "jekyll"
5+
gem "rack", ">= 2.1.4"
56
gem 'rack-jekyll'
67
gem 'rake'
78
gem 'jekyll-theme-minimal'

Gemfile.lock

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -59,11 +59,10 @@ GEM
5959
forwardable-extended (~> 2.6)
6060
posix-spawn (0.3.14)
6161
public_suffix (4.0.5)
62-
rack (1.6.13)
63-
rack-jekyll (0.5.0)
64-
jekyll (>= 1.3)
65-
listen (>= 1.3)
66-
rack (~> 1.5)
62+
rack (2.2.3)
63+
rack-jekyll (0.3.5)
64+
jekyll
65+
rack
6766
rake (13.0.1)
6867
rb-fsevent (0.10.4)
6968
rb-inotify (0.10.1)
@@ -90,6 +89,7 @@ DEPENDENCIES
9089
jekyll-seo-tag
9190
jekyll-sitemap
9291
jekyll-theme-minimal
92+
rack (>= 2.1.4)
9393
rack-jekyll
9494
rake
9595

0 commit comments

Comments
 (0)