From fdbfd0413e31e5b5ae0a78799b6a5682d88cd3ab Mon Sep 17 00:00:00 2001 From: Ben Abrams Date: Mon, 26 Mar 2018 14:03:10 -0700 Subject: [PATCH] [CVE-2017-17042] update vulnerable `yard` dependency Signed-off-by: Ben Abrams --- CHANGELOG.md | 3 +++ sensu-plugins-redis.gemspec | 2 +- 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 18902f1..358f629 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,9 @@ Which is based on [Keep A Changelog](http://keepachangelog.com/) ## [Unreleased] +### Security +- updated yard dependency to `~> 0.9.11` per: https://nvd.nist.gov/vuln/detail/CVE-2017-17042 (@majormoses) + ## [3.0.0] - 2018-03-17 ### Security - updated rubocop dependency to `~> 0.51.0` per: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8418. (@majormoses) diff --git a/sensu-plugins-redis.gemspec b/sensu-plugins-redis.gemspec index 9381f06..bb54d70 100644 --- a/sensu-plugins-redis.gemspec +++ b/sensu-plugins-redis.gemspec @@ -52,5 +52,5 @@ Gem::Specification.new do |s| # rubocop:disable Metrics/BlockLength s.add_development_dependency 'rubocop', '~> 0.51.0' s.add_development_dependency 'serverspec', '~> 2.36.1' s.add_development_dependency 'test-kitchen', '~> 1.16.0' - s.add_development_dependency 'yard', '~> 0.8' + s.add_development_dependency 'yard', '~> 0.9.11' end