SECURITY: update rack-mini-profiler to latest to correct XSS
This corrects an XSS in ?pp=help. Also removes the jQuery dependency from rack-mini-profiler and restricts memory sensitive profiling methods development only.
This commit is contained in:
parent
6e04120e71
commit
fd0bb34001
@ -267,7 +267,7 @@ GEM
|
||||
puma (3.12.1)
|
||||
r2 (0.2.7)
|
||||
rack (2.0.7)
|
||||
rack-mini-profiler (1.0.2)
|
||||
rack-mini-profiler (1.1.0)
|
||||
rack (>= 1.2.0)
|
||||
rack-openid (1.3.1)
|
||||
rack (>= 1.1.0)
|
||||
|
||||
Reference in New Issue
Block a user