From 856bfac3f17e5fe0afe3fd07c88e7ab59314dc93 Mon Sep 17 00:00:00 2001 From: Takuro Ashie Date: Thu, 8 Jul 2021 15:33:52 +0900 Subject: [PATCH] Relax http_parse.rb version http_parser.rb 0.6.0 includes a garbage Gemfile.lock and it causes false positive detection by security scanning tools. 0.7.0 fixes this issue. See also: #3374 #3409 #3437 Signed-off-by: Takuro Ashie --- fluentd.gemspec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fluentd.gemspec b/fluentd.gemspec index b5d622810e..924b45c962 100644 --- a/fluentd.gemspec +++ b/fluentd.gemspec @@ -23,7 +23,7 @@ Gem::Specification.new do |gem| gem.add_runtime_dependency("yajl-ruby", ["~> 1.0"]) gem.add_runtime_dependency("cool.io", [">= 1.4.5", "< 2.0.0"]) gem.add_runtime_dependency("serverengine", [">= 2.2.2", "< 3.0.0"]) - gem.add_runtime_dependency("http_parser.rb", [">= 0.5.1", "< 0.7.0"]) + gem.add_runtime_dependency("http_parser.rb", [">= 0.5.1", "< 0.8.0"]) gem.add_runtime_dependency("sigdump", ["~> 0.2.2"]) gem.add_runtime_dependency("tzinfo", [">= 1.0", "< 3.0"]) gem.add_runtime_dependency("tzinfo-data", ["~> 1.0"])