summaryrefslogtreecommitdiff
path: root/chef.gemspec
diff options
context:
space:
mode:
authorTim Smith <tsmith@chef.io>2018-11-15 12:02:46 -0800
committerTim Smith <tsmith@chef.io>2018-11-15 12:02:46 -0800
commitc8460b9a3659a6ffd0cea0297a956933743edd92 (patch)
treeecbd43c0ed6c303c31e04d49d65344b0b98f2d86 /chef.gemspec
parent5991cd84731a5c22e4ad411c38334b506d07ab9a (diff)
downloadchef-c8460b9a3659a6ffd0cea0297a956933743edd92.tar.gz
Require chef-zero 14.0.11 or later to resolve Rack gem CVEschef_zero_rack_cve
There are 2 CVEs in rack < 2.0.6. We now require at least 2.0.6 in chef-zero 14.0.11. This requires that version of chef-zero so we can ensure we don't bring in the Rack with CVEs. Signed-off-by: Tim Smith <tsmith@chef.io>
Diffstat (limited to 'chef.gemspec')
-rw-r--r--chef.gemspec2
1 files changed, 1 insertions, 1 deletions
diff --git a/chef.gemspec b/chef.gemspec
index 1db824c927..c787e00580 100644
--- a/chef.gemspec
+++ b/chef.gemspec
@@ -33,7 +33,7 @@ Gem::Specification.new do |s|
s.add_dependency "erubis", "~> 2.7"
s.add_dependency "diff-lcs", "~> 1.2", ">= 1.2.4"
- s.add_dependency "chef-zero", ">= 13.0"
+ s.add_dependency "chef-zero", ">= 14.0.11"
s.add_dependency "plist", "~> 3.2"
s.add_dependency "iniparse", "~> 1.4"