Bump activesupport, rails, actionmailer, actionpack, activerecord, activeresource, rack, rake, feedzirra, builder, loofah, sax-machine and nokogiri #16
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps activesupport, rails, actionmailer, actionpack, activerecord, activeresource, rack, rake, feedzirra, builder, loofah, sax-machine and nokogiri. These dependencies needed to be updated together.
Updates
activesupportfrom 2.3.8 to 7.0.4.2Release notes
Sourced from activesupport's releases.
... (truncated)
Changelog
Sourced from activesupport's changelog.
... (truncated)
Commits
7c70791Version 7.0.4.223e0345Version 7.0.4.12164d4fAvoid regex backtracking in Inflector.underscore8015c2cVersion 7.0.4ff27758Revert "Merge pull request #44695 from Edouard-chin/ec-tagger-logger-broadcast"4a1f224Merge pull request #45882 from rails/short-inspect-on-test-casea3bd3b5Backport Redis 5.0 compatibility67f37acFix flaky tests for RedisCacheStorec520e38Document AS::Cache::MemCacheStore#write options [ci-skip]a74b650Document AS::Cache::Store#initialize options [ci-skip]Updates
railsfrom 2.3.8 to 7.0.4.2Release notes
Sourced from rails's releases.
... (truncated)
Commits
7c70791Version 7.0.4.21d6de16Merge pull request #47087 from jhawthorn/cookie_domain23e0345Version 7.0.4.1d7aba06Make sanitize_as_sql_comment more strict8d82687Avoid regex backtracking on If-None-Match header2164d4fAvoid regex backtracking in Inflector.underscorecd46b0eUse string#split instead of regex for domain partse50e26dFix sec issue with _url_host_allowed?82bcdc0Added integer width check to PostgreSQL::Quoting8015c2cVersion 7.0.4Updates
actionmailerfrom 2.3.8 to 7.0.4.2Release notes
Sourced from actionmailer's releases.
... (truncated)
Changelog
Sourced from actionmailer's changelog.
... (truncated)
Commits
7c70791Version 7.0.4.223e0345Version 7.0.4.18015c2cVersion 7.0.404972d9Preparing for 7.0.3.1 release0c68c1fupdating version and changelog3872bc0Preparing for 7.0.3 releaseae98f49Merge pull request #44777 from jean-francois-labbe/mainc204039Merge branch '7-0-sec' into 7-0-stable3520cc7Preparing for 7.0.2.4 releasef2f7900updating changelog for releaseUpdates
actionpackfrom 2.3.8 to 7.0.4.2Release notes
Sourced from actionpack's releases.
... (truncated)
Changelog
Sourced from actionpack's changelog.
... (truncated)
Commits
7c70791Version 7.0.4.21d6de16Merge pull request #47087 from jhawthorn/cookie_domain23e0345Version 7.0.4.18d82687Avoid regex backtracking on If-None-Match headercd46b0eUse string#split instead of regex for domain partse50e26dFix sec issue with _url_host_allowed?8015c2cVersion 7.0.4f3c345eMerge pull request #45964 from jhawthorn/server_timing_safety4d25c64Merge pull request #45221 from jhawthorn/ac_params_eql_fix47cff40Format inline code [ci-skip]Updates
activerecordfrom 2.3.8 to 7.0.4.2Release notes
Sourced from activerecord's releases.
... (truncated)
Changelog
Sourced from activerecord's changelog.
... (truncated)
Commits
7c70791Version 7.0.4.223e0345Version 7.0.4.1d7aba06Make sanitize_as_sql_comment more strict82bcdc0Added integer width check to PostgreSQL::Quoting8015c2cVersion 7.0.44d9b4b4Merge pull request #45872 from the-spectator/correct_hwia_encodingc5a407dLinkify code references [ci-skip]e874cf5Fix typos [ci-skip]fb09b1bDon't handle this change for legacy_connection_handling0667ba4Merge pull request #45773 from eileencodes/only-setup-shared-pools-if-we-have...Updates
activeresourcefrom 2.3.8 to 6.0.0Release notes
Sourced from activeresource's releases.
... (truncated)
Commits
Updates
rackfrom 1.1.0 to 2.2.6.2Changelog
Sourced from rack's changelog.
... (truncated)
Commits
2606ac5bumping versionf6d4f52Fix ReDoS in Rack::Utils.get_byte_ranges20bc90cbump version3677f17Update changelogee25ab9Fix ReDoS vulnerability in multipart parser19e49f0Forbid control characters in attributesea39e49Bump patch version.c0f9de4Rack::MethodOverride handle QueryParser::ParamsTooDeepError (#2011)8312a2fRemove leading dot to fix compatibility with latest cgi gem. (#1988)2a82c88Update tests to work on latest Rubies. (#1999)Updates
rakefrom 0.8.7 to 13.0.6Release notes
Sourced from rake's releases.
... (truncated)
Changelog
Sourced from rake's changelog.
... (truncated)
Commits
5c60da8Bump up Rake-13.0.673d4099Merge pull request #390 from ruby/fix-388-again63aacb6Added Rake namespace explicitly29a3949Bump version to v13.0.53a95f4cMerge pull request #389 from ruby/fix-38885c55b4Fixed the regression of #38872ac796History for rake-13.0.4b20de78Bump version to 13.0.4a07e637Merge pull request #386 from ruby/cleanup0acc575Use require_relative to specify release versionUpdates
feedzirrafrom 0.0.24 to 0.8.0Changelog
Sourced from feedzirra's changelog.
... (truncated)
Commits
5ca1a2cDeprecate Feedzirra, use Feedjira instead18832a8Update CHANGELOG for 0.7.135baab5Bump version for 0.7.1293b49abe a new entry if feed not have entry id and only difference is a url6e075a8Update CHANGELOG for 0.7.00f863b1Bump version for 0.7.0e614278Bugfix for parsing dates that are ISO 8601 with millisecondsd552496On failure callbacks get curl and error as args260a979Movecall_on_failureto private method801b978Fix tests for #194Updates
builderfrom 2.1.2 to 3.2.4Changelog
Sourced from builder's changelog.
Commits
Updates
loofahfrom 0.4.7 to 2.19.1Release notes
Sourced from loofah's releases.
... (truncated)
Changelog
Sourced from loofah's changelog.
... (truncated)
Commits
3f88063version bump to v2.19.19a8dadbdocs: preserve the context and decision record86f7f63fix: replace recursive approach to cdata with escaping solution415677ffix: do not allow "image/svg+xml" in data URIs84ca20crefactor: extract scrub_uri_attribute for downstream use47a835aci: pin psych to v4 until v5 builds properly on CIa6e0a1afix: replace slow regex attribute check with crass parserea853aaMerge pull request #247 from flavorjones/flavorjones-downstream-test-rhse1f2a4bci: test downstream rails-html-sanitizer79d65a0Merge pull request #245 from flavorjones/flavorjones-fix-ruby-2.5-ciUpdates
sax-machinefrom 0.0.15 to 1.3.2Changelog
Sourced from sax-machine's changelog.
... (truncated)
Commits
Updates
nokogirifrom 1.4.3.1 to 1.14.1Release notes
Sourced from nokogiri's releases.
... (truncated)
Changelog
Sourced from