Skip to content

Commit fb694ae

Browse files
CCM-13769: dependencies
1 parent 6f6eab0 commit fb694ae

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

docs/Gemfile

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,3 +42,8 @@ gem 'sass-embedded', '1.78'
4242
gem 'jekyll-webpack'
4343

4444
gem 'rubocop', require: false
45+
46+
# Security: Explicit dependency pins to resolve CVEs
47+
gem 'google-protobuf', '>= 4.28.3' # Addresses CVE-2024-7254
48+
gem 'rexml', '>= 3.3.9' # Addresses CVE-2024-49761, CVE-2024-47220
49+
gem 'webrick', '~> 1.8' # Standard Ruby web server for Jekyll serve

0 commit comments

Comments
 (0)