From e2e996b3688c6245c4852b19992ae00b0d2095a8 Mon Sep 17 00:00:00 2001 From: Andrea Date: Thu, 4 Jan 2018 15:48:10 -0300 Subject: [PATCH] Updated minitar depencency Version: 0.5.4 Advisory: CVE-2016-10173 Criticality: Unknown URL: https://github.com/halostatue/minitar/issues/16 Title: Minitar Directory Traversal Vulnerability Solution: upgrade to >= 0.6.1 --- opzworks.gemspec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/opzworks.gemspec b/opzworks.gemspec index cfb9e05..0fbe150 100644 --- a/opzworks.gemspec +++ b/opzworks.gemspec @@ -44,7 +44,7 @@ Gem::Specification.new do |spec| spec.add_dependency 'json', '~> 1.8' spec.add_dependency 'berkshelf-api-client' spec.add_dependency 'cleanroom' - spec.add_dependency 'minitar', '~> 0.5.4' + spec.add_dependency 'minitar', '>= 0.6.1' spec.add_dependency 'mixlib-archive', '~> 0.2.0' spec.add_dependency 'octokit', '~> 4.6' spec.add_dependency 'sawyer', '~> 0.8'