fix(security): bump crass to 1.0.7

1.0.6 has four known DoS advisories (stack overflow / excessive CPU and memory on crafted CSS input) that were failing the bundler-audit CI job.

Seto Elkahfi committed Jul 5, 2026 at 09:45 UTC 9d028b57c9569527c26464304ef3db26ce6a17d0
1 file changed +1 -1
Gemfile.lock
+1 -1
@@ -94,7 +94,7 @@ GEM
94 logger (~> 1.5)
95 concurrent-ruby (1.3.7)
96 connection_pool (3.0.2)
97 - crass (1.0.6)
97 + crass (1.0.7)
98 date (3.5.1)
99 debug (1.11.1)
100 irb (~> 1.10)