Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.
Sign up🚨 [security] [ruby] Update all of rails: 5.2.2 → 5.2.2.1 (minor) #272
+42
−42
Conversation
depfu
bot
added
the
depfu
label
Mar 13, 2019
This comment has been minimized.
This comment has been minimized.
@depfu rebase |
ruebot
approved these changes
Mar 13, 2019
ruebot
merged commit 3fa1336
into
master
Mar 13, 2019
depfu
bot
deleted the
depfu/update/group/rails-5.2.2.1
branch
Mar 13, 2019
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
depfu bot commentedMar 13, 2019
Advisory: CVE-2019-5419
Disclosed: March 13, 2019
URL: https://groups.google.com/forum/#!topic/rubyonrails-security/GN7w9fFAQeI
Denial of Service Vulnerability in Action View
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
Commits
See the full diff on Github. The new version differs by 3 commits:
Prep release
Fix possible dev mode RCE
Only accept formats from registered mime types
Commits
See the full diff on Github. The new version differs by 3 commits:
Prep release
Fix possible dev mode RCE
Only accept formats from registered mime types
Commits
See the full diff on Github. The new version differs by 3 commits:
Prep release
Fix possible dev mode RCE
Only accept formats from registered mime types
Commits
See the full diff on Github. The new version differs by 3 commits:
Prep release
Fix possible dev mode RCE
Only accept formats from registered mime types
Commits
See the full diff on Github. The new version differs by 3 commits:
Prep release
Fix possible dev mode RCE
Only accept formats from registered mime types
Commits
See the full diff on Github. The new version differs by 3 commits:
Prep release
Fix possible dev mode RCE
Only accept formats from registered mime types
Commits
See the full diff on Github. The new version differs by 3 commits:
Prep release
Fix possible dev mode RCE
Only accept formats from registered mime types
Commits
See the full diff on Github. The new version differs by 3 commits:
Prep release
Fix possible dev mode RCE
Only accept formats from registered mime types
Commits
See the full diff on Github. The new version differs by 3 commits:
Prep release
Fix possible dev mode RCE
Only accept formats from registered mime types
Release Notes
1.1.5 (from changelog)
1.1.4 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
1.8.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 11 commits:
Bump version to 1.8.0
Fix and expand on documentation for :yield_returns_buffer
Rename return_buffer option to yield_returns_buffer
Modify test to work with new :return_buffer behavior
Flip `result` and `code` for :return_buffer option
Disable minitest plugins when testing
Modify spec to show how :return_buffer can be used when modifying buffers
Simplify test in attempt to get 1.8.7 passing
Add return_buffer option to CaptureEndEngine
Update the README with an example of how to write a method that works with capture_end (Fixes #15)
Remove has_rdoc from gemspec, since it is deprecated
Release Notes
0.4.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 20 commits:
Ignore pkg directory for releasing.
Release 0.4.2
Test against latest Rubies
Merge pull request #113 from y-yagi/test_against_rails_52
Specify Rails env in a test of `secret_key_base is not present`
Use `secret_key_base` instead of deprecated `secret_token`
Test against Rails 5.2
Allow configuration in initializers
Fix typo
Merge pull request #108 from fattymiller/uniq-equality
Merge pull request #109 from bradleybuda/master
Remove memoization of GlobalID::Identification#to_global_id
GlobalID::Identification clears memoized to_global_id on dup
minitest 5.11 crashes with old versions of rails
Ignore .lock files for tests
Array#uniq to correctly identify == GlobalIDs
[ci skip] Convert all samples back to Ruby.
No such thing as labels, all purpose, baby.
Merge pull request #106 from ideasasylum/ideasasylum-improved-expiration-readme
Improved documentation clarity around expiration
Release Notes
0.3.3 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 14 commits:
v0.3.3
update to shared-mime-info-1.10
Merge pull request #62 from junaruga/feature/minitest
Change testing framework from bacon to minitest.
Merge pull request #61 from GBH/patch-2
Gratipay is no longer a thing
Merge pull request #56 from GBH/patch-1
Merge pull request #59 from junaruga/hotfix/travis-rbx
Set available rbx name on Travis CI.
Merge pull request #58 from junaruga/feature/update-travis
Update .travis.yml.
Fixing API link and adding button to rubygems
Merge pull request #42 from jaredbeck/introduce_changelog
Docs: Introduce changelog
Commits
See the full diff on Github. The new version differs by 10 commits:
version bump to v2.4.0
update CHANGELOG in preparation for v2.4.0
update dev dependencies
Merge pull request #86 from eagletmt/skip-progress-when-chunked
Merge pull request #87 from halfbyte/patch-1
Make version in changelog fit release version.
Skip progress report when Content-Length is unavailable
update test:examples to libiconv 1.15
concourse: test most-recent two rubies
convert to using windows-ruby-dev-tools-release
Release Notes
1.10.1
1.10.0
1.9.1
1.9.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Commits
See the full diff on Github. The new version differs by 3 commits:
Prep release
Fix possible dev mode RCE
Only accept formats from registered mime types
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase
.All Depfu comment commands