🚨 [security] Update all of rails: 6.1.4.1 → 6.1.4.4 (patch) #191
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ rails (6.1.4.1 → 6.1.4.4) · Repo
Release Notes
6.1.4.4
6.1.4.3
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseSecurity Advisories 🚨
🚨 Possible Open Redirect in Host Authorization Middleware
Release Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
1.0.0
0.6.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 8 commits:
Prepare for 1.0.0Prepare to 0.6.0Upgrade all development gemsAdd devcontainer to allow contributors to have a working environmentMove ActiveRecord::FixtureSet.signed_global_id to this gemMerge pull request #137 from rails/dependabot/bundler/nokogiri-1.12.5Bump nokogiri from 1.11.7 to 1.12.5Why u no love me?Release Notes
1.8.11
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 9 commits:
Bump to 1.8.11Merge pull request #569 from koic/fix_build_error_when_using_psych_4_0Merge pull request #572 from codealchemy/simple_backend/json-test-fixFix typo in Simple backend JSON testFix a build error when using Psych 4.0Merge pull request #566 from codealchemy/simple_backend/consolidate-available-locale-checkUpdate available locale check in Simple backendMerge pull request #565 from rkh/patch-1Fix typo in documentationRelease Notes
2.13.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 7 commits:
version bump to v2.13.0Merge pull request #222 from flavorjones/221-fragment-text-should-not-serialize-commentfix: comments should not be emitted by DocumentFragment#textMerge pull request #220 from flavorjones/flavorjones-test-css-hex-encoded-exploittest: use CSS hex-encoded strings to test sanitizationMerge pull request #217 from gogainda/mainUpdate ci.ymlRelease Notes
1.0.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 34 commits:
v1.0.2v1.1.0Merge pull request #63 from brian-kephart/mainAdd AVIF to custom definitions to fix conflict with video/quicktimeAdd AVIF fixtureMerge pull request #60 from gmcgibbon/contributing_noteAdd generation note in tables.rbAdd contributing noteMerge pull request #58 from kiskoza/fix-audio/webmFix audio/webm filesMerge pull request #56 from andynguyenshopify/fix-musepackFix musepack files application/vnd.mophun.certificate -> audio/x-musepackMerge pull request #55 from kodokon/fix_markdownFix markdown file reporting to conform with IANA ->text/markdownMerge pull request #54 from gmcgibbon/application/x-ole-storagePrefer application/x-ole-storage instead of application/x-tika-msofficeMerge pull request #53 from gmcgibbon/mde_accdeAdd support for .mde and .accde filesMerge pull request #45 from gmcgibbon/wavPrefer audio/x-wav for .wav filesMerge pull request #51 from gmcgibbon/json_fixtureMerge pull request #50 from gmcgibbon/mdb_accdbMerge pull request #52 from gmcgibbon/sass_scssMerge pull request #49 from gmcgibbon/aacMerge pull request #46 from gmcgibbon/pemMerge pull request #47 from gmcgibbon/flacAdd support for scss and sass detectionFix JSON fixture syntaxFix detection for .mdb and .accdb filesPrefer audio/aac for .aac filesPrefer audio/flac for .flac filesPrefer application/x-x509-ca-cert for .pem filesFix syntaxRemove Travis CI configCommits
See the full diff on Github. The new version differs by 5 commits:
version bumpDB updates 2021-10-01T10:15:26Zversion bump and changelogDB updates 2021-08-01T10:14:51ZDEV: Allow recent versions of gems in developmentRelease Notes
5.15.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 17 commits:
prepped for release- Fixed #skip_until for windows paths. (MSP-Greg)- Fixed marshalling of specs if they error. (tenderlove, jeremyevans, et al)Added minitest-heat to readme. (garrettdimon)Added failing test to show specs can't marshal if they raise. (jeremyevans)- Updated deprecation message for block expectations. (blowmage)- Use Kernel.warn directly in expectations in case CUT defines their own warn. (firien)+ Use Etc.nprocessors by default in order to maximize cpu usage. (tonytonyjan)+ Enable Ruby deprecation warnings by default. (casperisfine)Fixed typo for 5.0.0 in History.rdoc. (tnir)- Close then unlink tempfiles on Windows. (nobu)+ Added -S <CODES> option to skip reporting of certain types of outputRuby 1.9 is a taaad dead by now.Use assert_match instead of assert_equal to test the error message. (mame)Added rematch plugin reference in README (ddnexus)! assert_throws returns the value returned, if any. (volmer)updated ruby version statusRelease Notes
1.4.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 8 commits:
version bump to v1.4.2Merge pull request #118 from rails/flavorjones-tweak-comment-and-piperf: PermitScrubber#scrub checks node.element? before node.comment?test: rewrite test coverage for comments and PIsci: update default git branchMerge pull request #119 from rails/flavorjones-port-ci-to-github-actionsci: remove travis and update the CI badgeci: add github actions workflowRelease Notes
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Preparing for 6.1.4.4 releasePreparing for 6.1.4.3 releasebumping version for releaseRelease Notes
3.4.2
3.4.1
3.4.0
3.3.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 30 commits:
Bump for 3.4.2Add `assets.resolve_assets_in_css_urls` configuration option to allow disabling `AssetUrlProcessor` (#489)Merge pull request #490 from ghiculescu/patch-1Update README.mdBe more explicit that `config.assets.debug` does nothing in Sprockets 4+Merge pull request #485 from PikachuEXE/fix/protocol-relative-urlsFix protocol relative URLs amended accidentallyBump for 3.4.1Fix sourcemapping url replacement (#484)Strip away the relative path (#482)Whitespaces :scissors:Merge pull request #474 from jbampton/fix-spellingMerge pull request #477 from jcoyne/rails-6.1Merge pull request #480 from zarqman/track-dependent-assetsRemove warning of unused variableBump for 3.4.0Process source mapping URLs be set by transpilers (#479)expose dependencies from AssetUrlProcessorBump for 3.3.0Process css files so that they get digested paths for asset files (#476)Test on Rails 6.1.xMerge pull request #475 from hahmed/ha/move-to-gitub-actionsFixes build for Gemfile, rails 7 by adding a new method that checks the rails version and appends media="screen" to the assertions. The setting config.action_view.apply_stylesheet_media_default = true was added in rails 7.Move to github actionsMerge pull request #472 from ghiculescu/use-the-good-errorRaise the error that includes an error messagechore: fix spellingMerge pull request #469 from skatkov/travis-remove-unsupported-versionsUpdate gemspec with minimum ruby/rails versionsTravis-ci: remove unsupported rubies and rails versionsRelease Notes
2.5.1 (from changelog)
2.5.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands
Go to the Depfu Dashboard to see the state of your dependencies and to customize how Depfu works.