π¨ [security] Update rails 7.0.8.4 β 7.1.5.1 (minor) #3540
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
π¨ Your current dependencies have known security vulnerabilities π¨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
β³οΈ rails (7.0.8.4 β 7.1.5.1) Β· Repo
Security Advisories π¨
π¨ Rails has possible XSS Vulnerability in Action Controller
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Security Advisories π¨
π¨ Possible ReDoS vulnerability in block_format in Action Mailer
π¨ Possible ReDoS vulnerability in block_format in Action Mailer
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Security Advisories π¨
π¨ Possible Content Security Policy bypass in Action Dispatch
π¨ Possible Content Security Policy bypass in Action Dispatch
π¨ Possible ReDoS vulnerability in query parameter filtering in Action Dispatch
π¨ Possible ReDoS vulnerability in HTTP Token authentication in Action Controller
π¨ Possible ReDoS vulnerability in HTTP Token authentication in Action Controller
π¨ Possible ReDoS vulnerability in query parameter filtering in Action Dispatch
π¨ Missing security headers in Action Pack on non-HTML responses
π¨ Rails has possible XSS Vulnerability in Action Controller
π¨ Rails has possible ReDoS vulnerability in Accept header parsing in Action Dispatch
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Security Advisories π¨
π¨ Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
π¨ Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
π¨ ActionText ContentAttachment can Contain Unsanitized HTML
π¨ Trix Editor Arbitrary Code Execution Vulnerability
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
0.5.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 28 commits:
π Bump version to 0.5.2
π Merge pull request #333 from nevans/basic-esearch-support
π₯ Workaround https://bugs.ruby-lang.org/issues/20956
β¨ Convert symbols & ranges in search return opts
β¨ Add keyword param for search `return` options
β¨ Gather ESEARCH response to #search/#uid_search
β¨ Parsing ESEARCH, with examples from RFC9051
β Copy `assert_pattern` from minitest
β¨ Add keyword argument for search charset
π Merge pull request #363 from ruby/search-charset-conflict-raise-argument_error
π₯ Raise ArgumentError on multiple search charset args
β»οΈ Extract search_args from search_internal
β Add some test coverage for search charset
β¨ Return empty SearchResult for no search result
β»οΈ Extract superclass for (internal) command data
π Consistent heading levels inside method rdoc
β¨ Add Data polyfill for ruby 3.1
π Update IMAP#search docs again
π Merge pull request #359 from ruby/enable-windows-test
Skip test_starttls_unknown_ca with Windows
Enabled windows-latest on GHA
β¬οΈ Bump step-security/harden-runner from 2.10.1 to 2.10.2 (#357)
ππ Fix rdoc 6.8 CSS styles
π¦ Add release.yml
π Merge pull request #354 from ruby/fix-README-example
π Update README example to use MOVE extension
π Fix broken example in README.md
π₯ Drop YAML.unsafe_load_file refinement (tests only)
Release Notes
1.17.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
version bump to v1.17.2
fix(jruby): XML::DocumentFragment.dup to another document (v1.17.x) (#3373)
fix(jruby): XML::DocumentFragment.dup to another document
Release Notes
1.6.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 2 commits:
version bump to v1.6.2
fix: PermitScrubber accepts frozen tags
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
0.4.3
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 9 commits:
Bump up v0.4.3
Merge pull request #51 from Cosmicoppai/co/timeout
Fixed version number of rubygems/release-gem
Merge pull request #55 from ruby/dependabot/github_actions/step-security/harden-runner-2.10.2
Merge pull request #54 from ruby/dependabot/github_actions/rubygems/release-gem-9e85cb11501bebc2ae661c1500176316d3987059
Bump step-security/harden-runner from 2.10.1 to 2.10.2
Bump rubygems/release-gem
removed the non numeric check
updated doc string
π benchmark (added, 0.4.0)
π connection_pool (added, 2.4.1)
π drb (added, 2.2.1)
π io-console (added, 0.8.0)
π irb (added, 1.14.2)
π mutex_m (added, 0.3.0)
π psych (added, 5.2.2)
π rack-session (added, 1.0.2)
π rackup (added, 1.0.1)
π rdoc (added, 6.9.1)
π reline (added, 0.6.0)
π securerandom (added, 0.4.1)
π stringio (added, 3.1.2)
π webrick (added, 1.9.1)
ποΈ method_source (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase
.All Depfu comment commands