Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion omnibus
15 changes: 15 additions & 0 deletions src/chef-server-ctl/Gemfile
Original file line number Diff line number Diff line change
Expand Up @@ -123,3 +123,18 @@ gem "rexml", ">= #{resolve_safe_version.call(:MINIMUM_SAFE_REXML_VERSION)}"
# of this bare floor only if a future ticket or test finding creates that
# second (cleanup) consumer.
gem "concurrent-ruby", ">= 1.3.8"

# faraday (CHEF-37252 / GHSA-98m9-hrrm-r99r [high], GHSA-5rv5-xj5j-3484 [low] --
# Dependabot alerts 385, 345). Declared as a plain, direct floor here -- NOT
# routed through the SafeVersions/resolve_safe_version mechanism above, unlike
# rack/rexml. That indirection exists specifically so ruby_gems_cleanup.rb (in
# chef-server-omnibus-config) and a Gemfile floor for the *same* gem can't drift
# apart -- it's a single source of truth for two consumers, not a generic place
# to declare any gem's minimum version. There is no ruby_gems_cleanup.rb entry
# for faraday (no ticket or on-disk test finding has established a
# stale/vulnerable-version-left-on-disk cleanup need for it, unlike
# rack/rexml/net-imap), so there is only one consumer here -- nothing for
# SafeVersions to keep in sync. Add a SafeVersions constant instead of this bare
# floor only if a future ticket or test finding creates that second (cleanup)
# consumer.
gem "faraday", ">= 2.14.3"
5 changes: 3 additions & 2 deletions src/chef-server-ctl/Gemfile.lock
Original file line number Diff line number Diff line change
Expand Up @@ -202,15 +202,15 @@ GEM
ed25519 (1.4.0)
erubi (1.13.1)
erubis (2.7.0)
faraday (2.14.1)
faraday (2.14.3)
faraday-net_http (>= 2.0, < 3.5)
json
logger
faraday-follow_redirects (0.5.0)
faraday (>= 1, < 3)
faraday-http-cache (2.5.1)
faraday (>= 0.8)
faraday-net_http (3.4.2)
faraday-net_http (3.4.4)
net-http (~> 0.5)
ffi (1.16.3)
ffi-libarchive (1.1.14)
Expand Down Expand Up @@ -512,6 +512,7 @@ DEPENDENCIES
chef-server-ctl!
chefstyle
concurrent-ruby (>= 1.3.8)
faraday (>= 2.14.3)
knife (~> 19.0.105)
knife-ec-backup (~> 3.0.8)
public_suffix (< 7.0)
Expand Down
7 changes: 7 additions & 0 deletions src/oc-id/Gemfile
Original file line number Diff line number Diff line change
Expand Up @@ -136,6 +136,13 @@ gem 'net-imap', ">= #{resolve_safe_version.call(:NET_IMAP_FIX_VERSION)}"
# resolve_safe_version.call(...)/safe_versions.rb.
gem 'concurrent-ruby', ">= 1.3.8"

# faraday (CHEF-37252 / GHSA-98m9-hrrm-r99r [high], GHSA-5rv5-xj5j-3484 [low] --
# Dependabot alerts 384, 344). Bare floor, same reasoning as
# src/chef-server-ctl/Gemfile's identical line: no ruby_gems_cleanup.rb consumer
# exists for this gem, so it does not go through
# resolve_safe_version.call(...)/safe_versions.rb.
gem 'faraday', ">= 2.14.3"

gem 'omniauth-chef', '~> 0.4.1',
git: "https://github.com/talktovikas/omniauth-chef.git",
branch: "vikas/chef-upgrade"
Expand Down
5 changes: 3 additions & 2 deletions src/oc-id/Gemfile.lock
Original file line number Diff line number Diff line change
Expand Up @@ -316,13 +316,13 @@ GEM
factory_bot_rails (6.5.1)
factory_bot (~> 6.5)
railties (>= 6.1.0)
faraday (2.14.1)
faraday (2.14.3)
faraday-net_http (>= 2.0, < 3.5)
json
logger
faraday-follow_redirects (0.5.0)
faraday (>= 1, < 3)
faraday-net_http (3.4.2)
faraday-net_http (3.4.4)
net-http (~> 0.5)
ffi (1.16.3)
ffi-libarchive (1.1.14)
Expand Down Expand Up @@ -769,6 +769,7 @@ DEPENDENCIES
config (~> 4.1)
doorkeeper (~> 5.0)
factory_bot_rails (~> 6.4)
faraday (>= 2.14.3)
jbuilder (~> 2.11)
jquery-rails
jwt (>= 3.2.0)
Expand Down
Loading