The htmltoword gem is using rubyzip >= 1.0 and we just got notified by GitHub that the dependency has a security vulnerability. Update both gems, rubyzip to >= 1.2.1 (specify in gemfile if needed) and htmltoword to >0.7.0 