Bump actionpack, rails, feedzirra, activerecord, activeresource, activesupport, rack, actionmailer, rake, builder, loofah, sax-machine and nokogiri #19
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps actionpack, rails, feedzirra, activerecord, activeresource, activesupport, rack, actionmailer, rake, builder, loofah, sax-machine and nokogiri. These dependencies needed to be updated together.
Updates
actionpackfrom 2.3.8 to 7.0.4.3Release notes
Sourced from actionpack's releases.
... (truncated)
Changelog
Sourced from actionpack's changelog.
... (truncated)
Commits
c15ee6ePreparing for 7.0.4.3 release7c70791Version 7.0.4.21d6de16Merge pull request #47087 from jhawthorn/cookie_domain23e0345Version 7.0.4.18d82687Avoid regex backtracking on If-None-Match headercd46b0eUse string#split instead of regex for domain partse50e26dFix sec issue with _url_host_allowed?8015c2cVersion 7.0.4f3c345eMerge pull request #45964 from jhawthorn/server_timing_safety4d25c64Merge pull request #45221 from jhawthorn/ac_params_eql_fixUpdates
railsfrom 2.3.8 to 7.0.4.3Release notes
Sourced from rails's releases.
... (truncated)
Commits
c15ee6ePreparing for 7.0.4.3 release73009eaIgnore certain data-* attributes in rails-ujs when element is contenteditable3468503Implement SafeBuffer#bytesplice7c70791Version 7.0.4.21d6de16Merge pull request #47087 from jhawthorn/cookie_domain23e0345Version 7.0.4.1d7aba06Make sanitize_as_sql_comment more strict8d82687Avoid regex backtracking on If-None-Match header2164d4fAvoid regex backtracking in Inflector.underscorecd46b0eUse string#split instead of regex for domain partsUpdates
feedzirrafrom 0.0.24 to 0.8.0Changelog
Sourced from feedzirra's changelog.
... (truncated)
Commits
5ca1a2cDeprecate Feedzirra, use Feedjira instead18832a8Update CHANGELOG for 0.7.135baab5Bump version for 0.7.1293b49abe a new entry if feed not have entry id and only difference is a url6e075a8Update CHANGELOG for 0.7.00f863b1Bump version for 0.7.0e614278Bugfix for parsing dates that are ISO 8601 with millisecondsd552496On failure callbacks get curl and error as args260a979Movecall_on_failureto private method801b978Fix tests for #194Updates
activerecordfrom 2.3.8 to 7.0.4.3Release notes
Sourced from activerecord's releases.
... (truncated)
Changelog
Sourced from activerecord's changelog.
... (truncated)
Commits
c15ee6ePreparing for 7.0.4.3 release7c70791Version 7.0.4.223e0345Version 7.0.4.1d7aba06Make sanitize_as_sql_comment more strict82bcdc0Added integer width check to PostgreSQL::Quoting8015c2cVersion 7.0.44d9b4b4Merge pull request #45872 from the-spectator/correct_hwia_encodingc5a407dLinkify code references [ci-skip]e874cf5Fix typos [ci-skip]fb09b1bDon't handle this change for legacy_connection_handlingUpdates
activeresourcefrom 2.3.8 to 6.0.0Release notes
Sourced from activeresource's releases.
... (truncated)
Commits
Updates
activesupportfrom 2.3.8 to 7.0.4.3Release notes
Sourced from activesupport's releases.
... (truncated)
Changelog
Sourced from activesupport's changelog.
... (truncated)
Commits
c15ee6ePreparing for 7.0.4.3 release3468503Implement SafeBuffer#bytesplice7c70791Version 7.0.4.223e0345Version 7.0.4.12164d4fAvoid regex backtracking in Inflector.underscore8015c2cVersion 7.0.4ff27758Revert "Merge pull request #44695 from Edouard-chin/ec-tagger-logger-broadcast"4a1f224Merge pull request #45882 from rails/short-inspect-on-test-casea3bd3b5Backport Redis 5.0 compatibility67f37acFix flaky tests for RedisCacheStoreUpdates
rackfrom 1.1.0 to 2.2.6.4Changelog
Sourced from rack's changelog.
... (truncated)
Commits
27addc7bump versionee7919eAvoid ReDoS problemd6b5b2bbump version9aac375Limit all multipart parts, not just files2606ac5bumping versionf6d4f52Fix ReDoS in Rack::Utils.get_byte_ranges20bc90cbump version3677f17Update changelogee25ab9Fix ReDoS vulnerability in multipart parser19e49f0Forbid control characters in attributesUpdates
actionmailerfrom 2.3.8 to 7.0.4.3Release notes
Sourced from actionmailer's releases.
... (truncated)
Changelog
Sourced from actionmailer's changelog.
... (truncated)
Commits
c15ee6ePreparing for 7.0.4.3 release7c70791Version 7.0.4.223e0345Version 7.0.4.18015c2cVersion 7.0.404972d9Preparing for 7.0.3.1 release0c68c1fupdating version and changelog3872bc0Preparing for 7.0.3 releaseae98f49Merge pull request #44777 from jean-francois-labbe/mainc204039Merge branch '7-0-sec' into 7-0-stable3520cc7Preparing for 7.0.2.4 releaseUpdates
rakefrom 0.8.7 to 13.0.6Release notes
Sourced from rake's releases.
... (truncated)
Changelog
Sourced from rake's changelog.
... (truncated)
Commits
5c60da8Bump up Rake-13.0.673d4099Merge pull request #390 from ruby/fix-388-again63aacb6Added Rake namespace explicitly29a3949Bump version to v13.0.53a95f4cMerge pull request #389 from ruby/fix-38885c55b4Fixed the regression of #38872ac796History for rake-13.0.4b20de78Bump version to 13.0.4a07e637Merge pull request #386 from ruby/cleanup0acc575Use require_relative to specify release versionUpdates
builderfrom 2.1.2 to 3.2.4Changelog
Sourced from builder's changelog.
Commits
Updates
loofahfrom 0.4.7 to 2.20.0Release notes
Sourced from loofah's releases.
... (truncated)
Changelog
Sourced from loofah's changelog.
... (truncated)
Commits
3d80a4eversion bump to v2.20.0c8211c1Merge pull request #260 from flavorjones/flavorjones-more-flexible-testing24dbde5test: make the generated tests more flexible6944760Merge pull request #259 from orien/ruby3.2f5ab30bCI: add Ruby 3.2 to the test matrixf8df852Merge pull request #257 from kyoshidajp/update-checkout-v3254a1c9Bump actions/checkout from 2 to 301305b6Merge pull request #255 from cjba7/cjba7-add-fax-to-acceptable-protocolsb0e6f7cdoc: update CHANGELOGed2c917Added "fax" and "modem" to acceptable protocols based on rfc2806.Updates
sax-machinefrom 0.0.15 to 1.3.2Changelog
Sourced from sax-machine's changelog.
... (truncated)
Commits
Updates
nokogirifrom 1.4.3.1 to 1.14.3Release notes
Sourced from nokogiri's releases.
... (truncated)
Changelog
Sourced from nokogiri's changelog.