Skip to content

checked for gem vulnerabilities and fixed a bug in search box#109

Open
pranibyna502 wants to merge 1 commit into
rails7-circleci-testfrom
gem-updates-rails7
Open

checked for gem vulnerabilities and fixed a bug in search box#109
pranibyna502 wants to merge 1 commit into
rails7-circleci-testfrom
gem-updates-rails7

Conversation

@pranibyna502
Copy link
Copy Markdown

Gem Updates, Security Patches, and Search Fix

Description

Updated rake to ~> 13.4 and spring-watcher-listen to ~> 2.1
Added explicit gem constraints for rack, faraday, nokogiri, rexml, and uri to address security vulnerabilities
Added required attribute to search input to prevent empty search submissions

Related Issue
Routine dependency maintenance and security patch check.
Motivation and Context
bundle audit flagged several gems with known CVEs, primarily around DoS vulnerabilities in rack and SSRF in faraday. Search box was throwing an error on empty submissions.
How Has This Been Tested?

Rebuilt Docker container and verified gem versions via bundle list
Ran full RSpec test suite — all tests passing
Manually tested search box with empty input — browser now prevents submission

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant