Skip to content

Commit 3a5b620

Browse files
committed
Changed "upgrade to" to "update to" to match bundle update (closes #394).
1 parent ae4e6ee commit 3a5b620

File tree

5 files changed

+13
-13
lines changed

5 files changed

+13
-13
lines changed

README.md

+7-7
Original file line numberDiff line numberDiff line change
@@ -31,55 +31,55 @@ Audit a project's `Gemfile.lock`:
3131
Criticality: Medium
3232
URL: http://www.osvdb.org/show/osvdb/91452
3333
Title: XSS vulnerability in sanitize_css in Action Pack
34-
Solution: upgrade to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
34+
Solution: update to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
3535

3636
Name: actionpack
3737
Version: 3.2.10
3838
Advisory: OSVDB-91454
3939
Criticality: Medium
4040
URL: http://osvdb.org/show/osvdb/91454
4141
Title: XSS Vulnerability in the `sanitize` helper of Ruby on Rails
42-
Solution: upgrade to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
42+
Solution: update to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
4343

4444
Name: actionpack
4545
Version: 3.2.10
4646
Advisory: OSVDB-89026
4747
Criticality: High
4848
URL: http://osvdb.org/show/osvdb/89026
4949
Title: Ruby on Rails params_parser.rb Action Pack Type Casting Parameter Parsing Remote Code Execution
50-
Solution: upgrade to ~> 2.3.15, ~> 3.0.19, ~> 3.1.10, >= 3.2.11
50+
Solution: update to ~> 2.3.15, ~> 3.0.19, ~> 3.1.10, >= 3.2.11
5151

5252
Name: activerecord
5353
Version: 3.2.10
5454
Advisory: OSVDB-91453
5555
Criticality: High
5656
URL: http://osvdb.org/show/osvdb/91453
5757
Title: Symbol DoS vulnerability in Active Record
58-
Solution: upgrade to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
58+
Solution: update to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
5959

6060
Name: activerecord
6161
Version: 3.2.10
6262
Advisory: OSVDB-90072
6363
Criticality: Medium
6464
URL: http://direct.osvdb.org/show/osvdb/90072
6565
Title: Ruby on Rails Active Record attr_protected Method Bypass
66-
Solution: upgrade to ~> 2.3.17, ~> 3.1.11, >= 3.2.12
66+
Solution: update to ~> 2.3.17, ~> 3.1.11, >= 3.2.12
6767

6868
Name: activerecord
6969
Version: 3.2.10
7070
Advisory: OSVDB-89025
7171
Criticality: High
7272
URL: http://osvdb.org/show/osvdb/89025
7373
Title: Ruby on Rails Active Record JSON Parameter Parsing Query Bypass
74-
Solution: upgrade to ~> 2.3.16, ~> 3.0.19, ~> 3.1.10, >= 3.2.11
74+
Solution: update to ~> 2.3.16, ~> 3.0.19, ~> 3.1.10, >= 3.2.11
7575

7676
Name: activesupport
7777
Version: 3.2.10
7878
Advisory: OSVDB-91451
7979
Criticality: High
8080
URL: http://www.osvdb.org/show/osvdb/91451
8181
Title: XML Parsing Vulnerability affecting JRuby users
82-
Solution: upgrade to ~> 3.1.12, >= 3.2.13
82+
Solution: update to ~> 3.1.12, >= 3.2.13
8383

8484
Unpatched versions found!
8585

lib/bundler/audit/cli/formats/junit.rb

+1-1
Original file line numberDiff line numberDiff line change
@@ -101,7 +101,7 @@ def bundle_title(result)
101101

102102
def advisory_solution(advisory)
103103
unless advisory.patched_versions.empty?
104-
"upgrade to #{advisory.patched_versions.map { |v| "'#{v}'" }.join(', ')}"
104+
"update to #{advisory.patched_versions.map { |v| "'#{v}'" }.join(', ')}"
105105
else
106106
"remove or disable this gem until a patch is available!"
107107
end

lib/bundler/audit/cli/formats/text.rb

+1-1
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,7 @@ def print_advisory(gem, advisory)
104104
end
105105

106106
unless advisory.patched_versions.empty?
107-
say "Solution: upgrade to ", :red
107+
say "Solution: update to ", :red
108108
say advisory.patched_versions.map { |v| "'#{v}'" }.join(', ')
109109
else
110110
say "Solution: ", :red

spec/cli/formats/junit_spec.rb

+2-2
Original file line numberDiff line numberDiff line change
@@ -240,8 +240,8 @@
240240
end
241241

242242
context "when Advisory#patched_versions is not empty" do
243-
it 'must print "Solution: upgrade to ..."' do
244-
expect(output).to include("Solution: upgrade to #{CGI.escapeHTML(advisory.patched_versions.map { |v| "'#{v}'" }.join(', '))}")
243+
it 'must print "Solution: update to ..."' do
244+
expect(output).to include("Solution: update to #{CGI.escapeHTML(advisory.patched_versions.map { |v| "'#{v}'" }.join(', '))}")
245245
end
246246
end
247247

spec/cli/formats/text_spec.rb

+2-2
Original file line numberDiff line numberDiff line change
@@ -229,8 +229,8 @@
229229
end
230230

231231
context "when Advisory#patched_versions is not empty" do
232-
it 'must print "Solution: upgrade to ..."' do
233-
expect(output_lines).to include("Solution: upgrade to #{advisory.patched_versions.map { |v| "'#{v}'" }.join(', ')}")
232+
it 'must print "Solution: update to ..."' do
233+
expect(output_lines).to include("Solution: update to #{advisory.patched_versions.map { |v| "'#{v}'" }.join(', ')}")
234234
end
235235
end
236236

0 commit comments

Comments
 (0)