Gemfile.lock
GIT remote: https://github.com/deliveroo/routemaster-client revision: 2430d8ed3f1b2f126ba1b4af2c665c5e04348058 branch: reset_client_connection specs: routemaster-client (3.1.1) faraday (>= 0.9.0) oj (~> 2.17) typhoeus (~> 1.1) wisper (~> 1.6.1) GIT remote: https://github.com/deliveroo/ruby-test-reporter.git revision: 457a6b9d630a5bc1b5246a9dd5801b28c817c812 specs: codeclimate-test-reporter (1.0.8) simplecov (<= 0.13) GEM remote: https://rubygems.org/ specs:Regular Expression Denial of Service in Addressable templates addressable (2.5.0) public_suffix (~> 2.0, >= 2.0.2) byebug (9.0.6) coderay (1.1.1) connection_pool (2.2.1) crack (0.4.3) safe_yaml (~> 1.0.0) diff-lcs (1.3) docile (1.1.5) dogapi (1.25.0) multi_json dotenv (2.2.0) ethon (0.10.1) ffi (>= 1.3.0) eventmachine (1.2.3) faraday (0.11.0) multipart-post (>= 1.2, < 3) faraday_middleware (0.11.0.1) faraday (>= 0.7.4, < 1.0) ffi (1.11.1) foreman (0.83.0) thor (~> 0.19.1) formatador (0.2.5) guard (2.14.1) formatador (>= 0.2.4) listen (>= 2.7, < 4.0) lumberjack (~> 1.0) nenv (~> 0.1) notiffany (~> 0.0) pry (>= 0.9.12) shellany (~> 0.0) thor (>= 0.18.1) guard-compat (1.2.1) guard-rspec (4.7.3) guard (~> 2.1) guard-compat (~> 1.1) rspec (>= 2.99.0, < 4.0) hashdiff (0.3.2) honeybadger (3.1.0)json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix) json (2.1.0) listen (3.1.5) rb-fsevent (~> 0.9, >= 0.9.4) rb-inotify (~> 0.9, >= 0.9.7) ruby_dep (~> 1.2) lumberjack (1.0.11) method_source (0.8.2) msgpack (1.1.0) multi_json (1.12.1) multipart-post (2.0.0) nenv (0.3.0) newrelic_rpm (3.18.1.330) notiffany (0.1.1) nenv (~> 0.1) shellany (~> 0.0) oj (2.18.2) pry (0.10.4) coderay (~> 1.1.0) method_source (~> 0.8.1) slop (~> 3.4) pry-byebug (3.4.2) byebug (~> 9.0) pry (~> 0.10) pry-remote (0.1.8) pry (~> 0.9) slop (~> 3.0) public_suffix (2.0.5)Keepalive Connections Causing Denial Of Service in puma
Information Exposure with Puma when used with Rails
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma
HTTP Request Smuggling in puma
HTTP Response Splitting vulnerability in puma
Keepalive thread overload/DoS in puma
HTTP Smuggling via Transfer-Encoding Header in Puma
HTTP Response Splitting (Early Hints) in Puma puma (3.7.1)Percent-encoded cookies can be used to overwrite existing prefixed cookie names
Possible shell escape sequence injection vulnerability in Rack
Directory traversal in Rack::Directory app bundled with Rack
Denial of service via header parsing in Rack
Denial of service via multipart parsing in Rack
Denial of Service Vulnerability in Rack Multipart Parsing
Denial of Service Vulnerability in Rack Content-Disposition parsing
Possible information leak / session hijack vulnerability rack (1.6.11) rack-protection (1.5.5) rack rack-ssl (1.4.1) rack rack-test (0.6.3) rack (>= 1.0) rb-fsevent (0.9.8) rb-inotify (0.9.8) ffi (>= 0.5.0) redis (3.3.3) redis-namespace (1.5.3) redis (~> 3.0, >= 3.0.4) rspec (3.5.0) rspec-core (~> 3.5.0) rspec-expectations (~> 3.5.0) rspec-mocks (~> 3.5.0) rspec-core (3.5.4) rspec-support (~> 3.5.0) rspec-expectations (3.5.0) diff-lcs (>= 1.2.0, < 2.0) rspec-support (~> 3.5.0) rspec-its (1.2.0) rspec-core (>= 3.0.0) rspec-expectations (>= 3.0.0) rspec-mocks (3.5.0) diff-lcs (>= 1.2.0, < 2.0) rspec-support (~> 3.5.0) rspec-support (3.5.0) ruby_dep (1.5.0) safe_yaml (1.0.4) sentry-raven (2.3.1) faraday (>= 0.7.6, < 1.0) shellany (0.0.1) simplecov (0.13.0) docile (~> 1.1.0) json (>= 1.8, < 3) simplecov-html (~> 0.10.0) simplecov-html (0.10.1)sinatra does not validate expanded path matches
Sinatra vulnerable to Reflected File Download attack sinatra (1.4.8) rack (~> 1.5) rack-protection (~> 1.4) tilt (>= 1.3, < 3) slop (3.6.0) thor (0.19.4) tilt (2.0.6) tunnels (1.2.2) eventmachine typhoeus (1.1.2) ethon (>= 0.9.0) webmock (2.3.2) addressable (>= 2.3.6) crack (>= 0.3.2) hashdiff wisper (1.6.1) PLATFORMS ruby DEPENDENCIES codeclimate-test-reporter! connection_pool dogapi dotenv faraday faraday_middleware foreman guard-rspec honeybadger msgpack newrelic_rpm oj pry pry-byebug pry-remote puma rack-ssl rack-test redis redis-namespace routemaster-client! rspec rspec-its sentry-raven sinatra tunnels typhoeus webmock RUBY VERSION ruby 2.3.3p222 BUNDLED WITH 1.16.5