summaryrefslogtreecommitdiff
path: root/omnibus_overrides.rb
diff options
context:
space:
mode:
authorTim Smith <tsmith84@gmail.com>2020-04-01 20:24:34 -0700
committerTim Smith <tsmith84@gmail.com>2020-04-01 21:40:11 -0700
commitd529fc0f453b09ef29d20e29db44ced850769123 (patch)
tree924ccf0b90e0d818bf9022d1341abc297217107c /omnibus_overrides.rb
parent4b728c6ec8ed4b4ab5ac4807de69f363566cb948 (diff)
downloadchef-d529fc0f453b09ef29d20e29db44ced850769123.tar.gz
Update Ruby to 2.6.6, Rake to 12.3.3 and libarchive to 3.4.2bumps_15
Ruby resolves 2 CVEs: https://www.ruby-lang.org/en/news/2020/03/31/ruby-2-6-6-released/ Rake is bundled in Ruby libarchive updated to 3.4.2 for multiple security issues including CVE-2019-19221 and CVE-2020-9308 Signed-off-by: Tim Smith <tsmith@chef.io>
Diffstat (limited to 'omnibus_overrides.rb')
-rw-r--r--omnibus_overrides.rb4
1 files changed, 2 insertions, 2 deletions
diff --git a/omnibus_overrides.rb b/omnibus_overrides.rb
index ccc012c0dc..f9285429f0 100644
--- a/omnibus_overrides.rb
+++ b/omnibus_overrides.rb
@@ -5,7 +5,7 @@
# software here: bundle exec rake dependencies:update_omnibus_gemfile_lock
override :rubygems, version: "3.0.3" # rubygems ships its own bundler which may differ from bundler defined below and then we get double bundler which results in performance issues / CLI warnings. Make sure these versions match before bumping either.
override :bundler, version: "1.17.2" # currently pinned to what ships in Ruby to prevent double bundler
-override "libarchive", version: "3.4.0"
+override "libarchive", version: "3.4.2"
override "libffi", version: "3.2.1"
override "libiconv", version: "1.15"
override "liblzma", version: "5.2.4"
@@ -18,7 +18,7 @@ override "ncurses", version: "5.9"
override "nokogiri", version: "1.10.5"
override "openssl", version: "1.0.2u"
override "pkg-config-lite", version: "0.28-1"
-override "ruby", version: "2.6.5"
+override "ruby", version: "2.6.6"
override "ruby-windows-devkit-bash", version: "3.1.23-4-msys-1.0.18"
override "util-macros", version: "1.19.0"
override "xproto", version: "7.0.28"