snyk-bot
dbcff5cadb
fix: Gemfile to reduce vulnerabilities
...
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-RUBY-NOKOGIRI-6228056
2024-02-15 21:02:45 +00:00
Kentaro Hayashi
aa959ceb9d
Merge pull request #384 from fluent/dependabot/bundler/nokogiri-1.12.5
...
Bump nokogiri from 1.12.1 to 1.12.5
2021-09-28 16:09:07 +09:00
dependabot[bot]
8871f80f42
Bump nokogiri from 1.12.1 to 1.12.5
...
Bumps [nokogiri](https://github.com/sparklemotion/nokogiri ) from 1.12.1 to 1.12.5.
- [Release notes](https://github.com/sparklemotion/nokogiri/releases )
- [Changelog](https://github.com/sparklemotion/nokogiri/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sparklemotion/nokogiri/compare/v1.12.1...v1.12.5 )
---
updated-dependencies:
- dependency-name: nokogiri
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2021-09-27 20:22:58 +00:00
Kentaro Hayashi
a4883e7d17
Merge pull request #379 from fluent/dependabot/npm_and_yarn/url-parse-1.5.3
...
Bump url-parse from 1.5.1 to 1.5.3
2021-08-13 18:17:39 +09:00
dependabot[bot]
2d03328c1f
Bump url-parse from 1.5.1 to 1.5.3
...
Bumps [url-parse](https://github.com/unshiftio/url-parse ) from 1.5.1 to 1.5.3.
- [Release notes](https://github.com/unshiftio/url-parse/releases )
- [Commits](https://github.com/unshiftio/url-parse/compare/1.5.1...1.5.3 )
---
updated-dependencies:
- dependency-name: url-parse
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2021-08-13 09:15:10 +00:00
Kentaro Hayashi
9e4a92d47f
Merge pull request #378 from fluent/dependabot/npm_and_yarn/path-parse-1.0.7
...
Bump path-parse from 1.0.6 to 1.0.7
2021-08-13 18:14:19 +09:00
dependabot[bot]
23d5edf009
Bump path-parse from 1.0.6 to 1.0.7
...
Bumps [path-parse](https://github.com/jbgutierrez/path-parse ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/jbgutierrez/path-parse/releases )
- [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7 )
---
updated-dependencies:
- dependency-name: path-parse
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2021-08-10 22:31:56 +00:00
Kentaro Hayashi
d0a327e68b
Merge pull request #377 from fluent/dependabot/bundler/puma-5.4.0
...
Bump puma from 4.3.5 to 5.4.0
2021-08-10 11:22:48 +09:00
dependabot[bot]
497a3efd9a
Bump puma from 4.3.5 to 5.4.0
...
Bumps [puma](https://github.com/puma/puma ) from 4.3.5 to 5.4.0.
- [Release notes](https://github.com/puma/puma/releases )
- [Changelog](https://github.com/puma/puma/blob/master/History.md )
- [Commits](https://github.com/puma/puma/compare/v4.3.5...v5.4.0 )
---
updated-dependencies:
- dependency-name: puma
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2021-08-04 05:33:47 +00:00
Kentaro Hayashi
a7ff483f54
Merge pull request #363 from fluent/dependabot/bundler/actionpack-5.2.6
...
Bump actionpack from 5.2.4.5 to 5.2.6
2021-08-04 14:33:00 +09:00
Kentaro Hayashi
83d6959206
Merge pull request #372 from fluent/dependabot/npm_and_yarn/ws-6.2.2
...
Bump ws from 6.2.1 to 6.2.2
2021-08-04 14:25:30 +09:00
dependabot[bot]
9be6d959ca
Bump actionpack from 5.2.4.5 to 5.2.6
...
Bumps [actionpack](https://github.com/rails/rails ) from 5.2.4.5 to 5.2.6.
- [Release notes](https://github.com/rails/rails/releases )
- [Changelog](https://github.com/rails/rails/blob/v6.1.3.2/actionpack/CHANGELOG.md )
- [Commits](https://github.com/rails/rails/compare/v5.2.4.5...v5.2.6 )
Signed-off-by: dependabot[bot] <support@github.com>
2021-08-04 05:25:22 +00:00
Kentaro Hayashi
bfcdaec5a6
Merge pull request #364 from fluent/dependabot/npm_and_yarn/lodash-4.17.21
...
Bump lodash from 4.17.19 to 4.17.21
2021-08-04 14:24:13 +09:00
dependabot[bot]
7c8ca77540
Bump lodash from 4.17.19 to 4.17.21
...
Bumps [lodash](https://github.com/lodash/lodash ) from 4.17.19 to 4.17.21.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.19...4.17.21 )
Signed-off-by: dependabot[bot] <support@github.com>
2021-08-03 08:20:28 +00:00
Kentaro Hayashi
02a9121be0
Merge pull request #366 from fluent/dependabot/npm_and_yarn/codemirror-5.58.2
...
Bump codemirror from 5.37.0 to 5.58.2
2021-08-03 17:19:28 +09:00
Kentaro Hayashi
3b3dac8dec
Merge pull request #367 from fluent/dependabot/bundler/nokogiri-1.11.4
...
Bump nokogiri from 1.11.1 to 1.11.4
2021-08-03 17:17:35 +09:00
dependabot[bot]
7a39fc9d1f
Bump ws from 6.2.1 to 6.2.2
...
Bumps [ws](https://github.com/websockets/ws ) from 6.2.1 to 6.2.2.
- [Release notes](https://github.com/websockets/ws/releases )
- [Commits](https://github.com/websockets/ws/commits )
---
updated-dependencies:
- dependency-name: ws
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2021-08-03 08:17:34 +00:00
Kentaro Hayashi
6ea1df69b7
Merge pull request #370 from fluent/dependabot/npm_and_yarn/browserslist-4.16.6
...
Bump browserslist from 4.16.4 to 4.16.6
2021-08-03 17:16:04 +09:00
Kentaro Hayashi
56181507a9
Merge pull request #371 from fluent/dependabot/npm_and_yarn/dns-packet-1.3.4
...
Bump dns-packet from 1.3.1 to 1.3.4
2021-08-03 17:15:30 +09:00
Kentaro Hayashi
7fa4221974
Merge pull request #373 from fluent/dependabot/npm_and_yarn/postcss-7.0.36
...
Bump postcss from 7.0.35 to 7.0.36
2021-08-03 17:14:07 +09:00
Kentaro Hayashi
e0ca5b060c
Merge pull request #374 from fluent/dependabot/bundler/addressable-2.8.0
...
Bump addressable from 2.5.2 to 2.8.0
2021-08-03 17:13:28 +09:00
dependabot[bot]
98a851106f
Bump addressable from 2.5.2 to 2.8.0
...
Bumps [addressable](https://github.com/sporkmonger/addressable ) from 2.5.2 to 2.8.0.
- [Release notes](https://github.com/sporkmonger/addressable/releases )
- [Changelog](https://github.com/sporkmonger/addressable/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sporkmonger/addressable/compare/addressable-2.5.2...addressable-2.8.0 )
---
updated-dependencies:
- dependency-name: addressable
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2021-07-12 17:18:01 +00:00
dependabot[bot]
c0e4ef202b
Bump postcss from 7.0.35 to 7.0.36
...
Bumps [postcss](https://github.com/postcss/postcss ) from 7.0.35 to 7.0.36.
- [Release notes](https://github.com/postcss/postcss/releases )
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md )
- [Commits](https://github.com/postcss/postcss/compare/7.0.35...7.0.36 )
---
updated-dependencies:
- dependency-name: postcss
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2021-06-15 19:59:52 +00:00
dependabot[bot]
210cc969d6
Bump dns-packet from 1.3.1 to 1.3.4
...
Bumps [dns-packet](https://github.com/mafintosh/dns-packet ) from 1.3.1 to 1.3.4.
- [Release notes](https://github.com/mafintosh/dns-packet/releases )
- [Changelog](https://github.com/mafintosh/dns-packet/blob/master/CHANGELOG.md )
- [Commits](https://github.com/mafintosh/dns-packet/compare/v1.3.1...v1.3.4 )
Signed-off-by: dependabot[bot] <support@github.com>
2021-05-27 08:12:05 +00:00
Kentaro Hayashi
38f66465a9
Merge pull request #362 from fluent/dependabot/bundler/rexml-3.2.5
...
Bump rexml from 3.2.4 to 3.2.5
2021-05-25 15:44:31 +09:00
dependabot[bot]
674d3f4db2
Bump browserslist from 4.16.4 to 4.16.6
...
Bumps [browserslist](https://github.com/browserslist/browserslist ) from 4.16.4 to 4.16.6.
- [Release notes](https://github.com/browserslist/browserslist/releases )
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md )
- [Commits](https://github.com/browserslist/browserslist/compare/4.16.4...4.16.6 )
Signed-off-by: dependabot[bot] <support@github.com>
2021-05-25 00:51:43 +00:00
dependabot[bot]
7ab99cc729
Bump nokogiri from 1.11.1 to 1.11.4
...
Bumps [nokogiri](https://github.com/sparklemotion/nokogiri ) from 1.11.1 to 1.11.4.
- [Release notes](https://github.com/sparklemotion/nokogiri/releases )
- [Changelog](https://github.com/sparklemotion/nokogiri/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sparklemotion/nokogiri/compare/v1.11.1...v1.11.4 )
Signed-off-by: dependabot[bot] <support@github.com>
2021-05-17 22:18:09 +00:00
dependabot[bot]
94dc9e0a72
Bump codemirror from 5.37.0 to 5.58.2
...
Bumps [codemirror](https://github.com/codemirror/CodeMirror ) from 5.37.0 to 5.58.2.
- [Release notes](https://github.com/codemirror/CodeMirror/releases )
- [Changelog](https://github.com/codemirror/CodeMirror/blob/master/CHANGELOG.md )
- [Commits](https://github.com/codemirror/CodeMirror/compare/5.37.0...5.58.2 )
Signed-off-by: dependabot[bot] <support@github.com>
2021-05-12 00:32:59 +00:00
dependabot[bot]
0b0eac4da2
Bump rexml from 3.2.4 to 3.2.5
...
Bumps [rexml](https://github.com/ruby/rexml ) from 3.2.4 to 3.2.5.
- [Release notes](https://github.com/ruby/rexml/releases )
- [Changelog](https://github.com/ruby/rexml/blob/master/NEWS.md )
- [Commits](https://github.com/ruby/rexml/compare/v3.2.4...v3.2.5 )
Signed-off-by: dependabot[bot] <support@github.com>
2021-04-30 22:09:29 +00:00
Kentaro Hayashi
6e6d339b56
Merge pull request #361 from kenhys/upgrade-datatables-bs4
...
Upgrade to datatables.net-bs4
2021-04-15 14:44:04 +09:00
Kentaro Hayashi
cb5a07c862
Upgrade to datatables.net-bs4
...
$ yarn upgrade datatables.net-bs4@1.10.24
The vulnerable version of datatables.net 1.10.19 is not used anymore.
Signed-off-by: Kentaro Hayashi <kenhys@gmail.com>
2021-04-15 14:37:01 +09:00
Kentaro Hayashi
4f607ab0a8
Merge pull request #359 from kenhys/add-githubactions
...
Migrate CI from Travis-CI to GitHub Actions
2021-04-15 14:09:52 +09:00
Kentaro Hayashi
aa743beb21
Migrate from Travis-CI to GitHub Actions
...
Signed-off-by: Kentaro Hayashi <kenhys@gmail.com>
2021-04-15 12:53:04 +09:00
Kentaro Hayashi
26e0794993
Merge pull request #358 from kenhys/upgrade-datatables-net
...
Upgrade datatables.net
2021-04-15 12:51:24 +09:00
Kentaro Hayashi
c90d7f3a6b
Upgrade datatables.net
...
datatables.net 1.10.19 is vulnerable version, but it was hold by
datatables.net-bs4 1.10.19.
startbootstrap-sb-admin should be upgraded because datatables.net-bs4
was hold by it.
Signed-off-by: Kentaro Hayashi <kenhys@gmail.com>
2021-04-15 12:49:20 +09:00
Kentaro Hayashi
e10cfe548e
Merge pull request #357 from kenhys/upgrade-node-forge
...
Upgrade webpack-dev-server
2021-04-15 12:41:19 +09:00
Kentaro Hayashi
c393f83596
Upgrade webpack-dev-server
...
node-forge 0.7.5 is vulnerable but it was hold by selfsigned 1.10.3.
webpack-dev-server must be upgraded because selfsigned was also bound
by it.
Signed-off-by: Kentaro Hayashi <kenhys@gmail.com>
2021-04-15 12:40:11 +09:00
Kentaro Hayashi
7f0202ac02
Merge pull request #356 from kenhys/drop-ruby24-ci
...
Drop Ruby 2.4 support
2021-04-15 12:09:59 +09:00
Kentaro Hayashi
d007b5a136
Drop Ruby 2.4 support
...
As Ruby 2.4 had already reached EOL
TODO: migrate Travis CI to GitHub Actions
Signed-off-by: Kentaro Hayashi <kenhys@gmail.com>
2021-04-15 12:02:10 +09:00
Kentaro Hayashi
5428c2ad3e
Merge pull request #355 from kenhys/upgrade-webmock
...
Use latest webmock
2021-04-15 11:59:31 +09:00
Kentaro Hayashi
73d1bb52b9
Use latest webmock
...
It is required to support recent Ruby.
NOTE:
* Ruby 2.6: Webmock 3.5.0 or later
* Ruby 2.7: Webmock 3.8.0 or later
Ruby 2.4 support was dropped since Webmock 3.9.0
Signed-off-by: Kentaro Hayashi <kenhys@gmail.com>
2021-04-15 11:50:16 +09:00
Kentaro Hayashi
4f46143953
Merge pull request #354 from kenhys/fix-missing-setting-parameters
...
Fix test failure by missing expected parameters
2021-04-15 11:38:44 +09:00
Kentaro Hayashi
879ef010e6
Fix test failure by missing parameters
...
It fixes the following test
Failure: test: .initial_params(Fluentd::Setting::InForwardTest)
/work/fluentd/fluentdui/fluentd-ui/test/models/fluentd/setting/in_forward_test.rb:62:in `block in <class:InForwardTest>'
59: }
60: },
61: }
=> 62: assert_equal(expected, @klass.initial_params)
63: end
64:
65: test "#valid?" do
<{:backlog=>nil,
Signed-off-by: Kentaro Hayashi <kenhys@gmail.com>
2021-04-14 18:04:43 +09:00
Kentaro Hayashi
0830cdd3dc
Merge pull request #353 from kenhys/upgrade-rails-webpacker
...
Fix node-sass related vulnerability
2021-04-14 16:51:37 +09:00
Kentaro Hayashi
3774bd89e8
Fix node-sass related vulnerability
...
$ yarn upgrade @rails/webpacker
node-sass ^4.11.0 has a security vulnerability, so
it should be 4.13.1 or later, but node-sass was hold by
@rails/webpacker, so webpacker should be upgraded first.
Signed-off-by: Kentaro Hayashi <kenhys@gmail.com>
2021-04-14 16:40:41 +09:00
Kentaro Hayashi
b8fb0f482e
Merge pull request #339 from fluent/dependabot/npm_and_yarn/http-proxy-1.18.1
...
Bump http-proxy from 1.17.0 to 1.18.1
2021-04-14 15:44:36 +09:00
Kentaro Hayashi
32a6cc66a3
Merge pull request #340 from fluent/dependabot/npm_and_yarn/node-fetch-2.6.1
...
Bump node-fetch from 2.3.0 to 2.6.1
2021-04-14 15:43:46 +09:00
Kentaro Hayashi
d5dcf190d7
Merge pull request #343 from fluent/dependabot/npm_and_yarn/ini-1.3.7
...
Bump ini from 1.3.5 to 1.3.7
2021-04-14 15:42:14 +09:00
Kentaro Hayashi
c9944dd520
Merge pull request #346 from fluent/dependabot/bundler/activerecord-5.2.4.5
...
Bump activerecord from 5.2.4.3 to 5.2.4.5
2021-04-14 15:36:37 +09:00
Kentaro Hayashi
c19bf374dc
Merge pull request #347 from fluent/dependabot/npm_and_yarn/elliptic-6.5.4
...
Bump elliptic from 6.4.0 to 6.5.4
2021-04-14 15:32:24 +09:00