-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency rails to v5 #26
Open
dev-mend-for-github-com
wants to merge
1
commit into
main
Choose a base branch
from
whitesource-remediate/rails-5.x
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
dev-mend-for-github-com
bot
added
the
security fix
Security fix generated by Mend
label
Mar 15, 2023
⚠ Artifact update problemRenovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
The artifact failure details are included below: File name: Gemfile.lock
|
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5
Update dependency rails to v5 - autoclosed
Jul 10, 2024
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5 - autoclosed
Update dependency rails to v5
Jul 10, 2024
dev-mend-for-github-com
bot
force-pushed
the
whitesource-remediate/rails-5.x
branch
from
July 10, 2024 04:18
e3ff073
to
f955b5e
Compare
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5
Update dependency rails to v5 - autoclosed
Jul 10, 2024
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5 - autoclosed
Update dependency rails to v5
Jul 10, 2024
dev-mend-for-github-com
bot
force-pushed
the
whitesource-remediate/rails-5.x
branch
from
July 10, 2024 07:48
f955b5e
to
42c2584
Compare
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5
Update dependency rails to v5 - autoclosed
Jul 11, 2024
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5 - autoclosed
Update dependency rails to v5
Jul 11, 2024
dev-mend-for-github-com
bot
force-pushed
the
whitesource-remediate/rails-5.x
branch
from
July 11, 2024 17:19
42c2584
to
3205efc
Compare
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5
Update dependency rails to v5 - autoclosed
Jul 14, 2024
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5 - autoclosed
Update dependency rails to v5
Jul 14, 2024
dev-mend-for-github-com
bot
force-pushed
the
whitesource-remediate/rails-5.x
branch
from
July 14, 2024 01:02
3205efc
to
d0b8b64
Compare
dev-mend-for-github-com
bot
force-pushed
the
whitesource-remediate/rails-5.x
branch
from
September 2, 2024 05:28
b873e8c
to
3dc6c5c
Compare
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5
Update dependency rails to v5 - autoclosed
Sep 2, 2024
dev-mend-for-github-com
bot
deleted the
whitesource-remediate/rails-5.x
branch
September 2, 2024 15:34
dev-mend-for-github-com
bot
restored the
whitesource-remediate/rails-5.x
branch
September 2, 2024 15:48
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5 - autoclosed
Update dependency rails to v5
Sep 2, 2024
dev-mend-for-github-com
bot
force-pushed
the
whitesource-remediate/rails-5.x
branch
from
September 2, 2024 15:48
3dc6c5c
to
16def54
Compare
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5
Update dependency rails to v5 - autoclosed
Sep 5, 2024
dev-mend-for-github-com
bot
deleted the
whitesource-remediate/rails-5.x
branch
September 5, 2024 21:38
dev-mend-for-github-com
bot
restored the
whitesource-remediate/rails-5.x
branch
September 5, 2024 21:52
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5 - autoclosed
Update dependency rails to v5
Sep 5, 2024
dev-mend-for-github-com
bot
force-pushed
the
whitesource-remediate/rails-5.x
branch
from
September 5, 2024 21:53
16def54
to
e8c272c
Compare
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5
Update dependency rails to v5 - autoclosed
Sep 8, 2024
dev-mend-for-github-com
bot
deleted the
whitesource-remediate/rails-5.x
branch
September 8, 2024 18:33
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5 - autoclosed
Update dependency rails to v5
Sep 8, 2024
dev-mend-for-github-com
bot
restored the
whitesource-remediate/rails-5.x
branch
September 8, 2024 18:48
dev-mend-for-github-com
bot
force-pushed
the
whitesource-remediate/rails-5.x
branch
from
September 8, 2024 18:49
e8c272c
to
0dd74fc
Compare
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5
Update dependency rails to v5 - autoclosed
Sep 10, 2024
dev-mend-for-github-com
bot
deleted the
whitesource-remediate/rails-5.x
branch
September 10, 2024 15:31
dev-mend-for-github-com
bot
changed the title
Update dependency rails to v5 - autoclosed
Update dependency rails to v5
Sep 11, 2024
dev-mend-for-github-com
bot
restored the
whitesource-remediate/rails-5.x
branch
September 11, 2024 07:02
dev-mend-for-github-com
bot
force-pushed
the
whitesource-remediate/rails-5.x
branch
from
September 11, 2024 07:03
0dd74fc
to
0c1fd8d
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
'3.0.7'
->'5.2.4.3'
By merging this PR, the issue #8 will be automatically resolved and closed:
Release Notes
rails/rails (rails)
v5.2.4.3
: 5.2.4.3Compare Source
Active Support
[CVE-2020-8165] Deprecate Marshal.load on raw cache read in RedisCacheStore
[CVE-2020-8165] Avoid Marshal.load on raw cache value in MemCacheStore
Active Model
Active Record
Action View
Action Pack
[CVE-2020-8166] HMAC raw CSRF token before masking it, so it cannot be used to reconstruct a per-form token
[CVE-2020-8164] Return self when calling #each, #each_pair, and #each_value instead of the raw @parameters hash
Active Job
Action Mailer
Action Cable
Active Storage
Railties
v5.2.4.2
: 5.2.4.2Compare Source
Active Support
Active Model
Active Record
Action View
Fix possible XSS vector in
escape_javascript
helperCVE-2020-5267
Aaron Patterson
Action Pack
Active Job
Action Mailer
Action Cable
Active Storage
Railties
v5.2.4.1
: 5.2.4.1Compare Source
Active Support
Active Model
Active Record
Action View
Action Pack
Fix possible information leak / session hijacking vulnerability.
The
ActionDispatch::Session::MemcacheStore
is still vulnerable given it requires thegem dalli to be updated as well.
CVE-2019-16782.
Active Job
Action Mailer
Action Cable
Active Storage
Railties
v5.2.4
: 5.2.4Compare Source
Active Support
Make ActiveSupport::Logger Fiber-safe. Fixes #36752.
Use
Fiber.current.__id__
inActiveSupport::Logger#local_level=
in orderto make log level local to Ruby Fibers in addition to Threads.
Example:
Before:
After:
Alexander Varnin
Active Model
Type cast falsy boolean symbols on boolean attribute as false.
Fixes #35676.
Ryuta Kamizono
Active Record
Fix circular
autosave: true
causes invalid records to be saved.Prior to the fix, when there was a circular series of
autosave: true
associations, the callback for a
has_many
association was run whileanother instance of the same callback on the same association hadn't
finished running. When control returned to the first instance of the
callback, the instance variable had changed, and subsequent associated
records weren't saved correctly. Specifically, the ID field for the
belongs_to
corresponding to thehas_many
wasnil
.Fixes #28080.
Larry Reid
PostgreSQL: Fix GROUP BY with ORDER BY virtual count attribute.
Fixes #36022.
Ryuta Kamizono
Fix sqlite3 collation parsing when using decimal columns.
Martin R. Schuster
Make ActiveRecord
ConnectionPool.connections
method thread-safe.Fixes #36465.
Jeff Doering
Assign all attributes before calling
build
to ensure the child record is visible inbefore_add
andafter_add
callbacks forhas_many :through
associations.Fixes #33249.
Ryan H. Kerr
Action View
Allow programmatic click events to trigger Rails UJS click handlers.
Programmatic click events (eg. ones generated by
Rails.fire(link, "click")
) don't specify a button. These events were being incorrectly stopped by code meant to ignore scroll wheel and right clicks introduced in #34573.Sudara Williams
Action Pack
Active Job
Action Mailer
Action Cable
Active Storage
Railties
Use original
bundler
environment variables during the process of generating a new rails project.Marco Costa
Allow loading seeds without ActiveJob.
Fixes #35782
Jeremy Weathers
Only force
:async
ActiveJob adapter to:inline
during seeding.BatedUrGonnaDie
v5.2.3
: 5.2.3Compare Source
Active Support
Add
ActiveSupport::HashWithIndifferentAccess#assoc
.assoc
can now be called with either a string or a symbol.Stefan Schüßler
Fix
String#safe_constantize
throwing aLoadError
for incorrectly cased constant references.Keenan Brock
Allow Range#=== and Range#cover? on Range
Range#cover?
can now accept a range argument likeRange#include?
andRange#===
.Range#===
works correctly on Ruby 2.6.Range#include?
is movedinto a new file, with these two methods.
utilum
If the same block is
included
multiple times for a Concern, an exception is no longer raised.Mark J. Titorenko, Vlad Bokov
Active Model
Fix date value when casting a multiparameter date hash to not convert
from Gregorian date to Julian date.
Before:
After:
Fixes #28521.
Sayan Chakraborty
Fix numericality equality validation of
BigDecimal
andFloat
by casting to
BigDecimal
on both ends of the validation.Gannon McGibbon
Active Record
Fix different
count
calculation when usingsize
with manualselect
with DISTINCT.Fixes #35214.
Juani Villarejo
Fix prepared statements caching to be enabled even when query caching is enabled.
Ryuta Kamizono
Don't allow
where
with invalid value matches to nil values.Fixes #33624.
Ryuta Kamizono
Restore an ability that class level
update
without giving ids.Fixes #34743.
Ryuta Kamizono
Fix join table column quoting with SQLite.
Gannon McGibbon
Ensure that
delete_all
on collection proxy returns affected count.Ryuta Kamizono
Reset scope after delete on collection association to clear stale offsets of removed records.
Gannon McGibbon
Action View
Prevent non-primary mouse keys from triggering Rails UJS click handlers.
Firefox fires click events even if the click was triggered by non-primary mouse keys such as right- or scroll-wheel-clicks.
For example, right-clicking a link such as the one described below (with an underlying ajax request registered on click) should not cause that request to occur.
Fixes #34541
Wolfgang Hobmaier
Action Pack
Allow using combine the Cache Control
public
andno-cache
headers.Before this change, even if
public
was specified for Cache Control header,it was excluded when
no-cache
was included. This fixed to keeppublic
header as is.
Fixes #34780.
Yuji Yaginuma
Allow
nil
params forActionController::TestCase
.Ryo Nakamura
Active Job
Action Mailer
Action Cable
Active Storage
Railties
Seed database with inline ActiveJob job adapter.
Gannon McGibbon
Fix boolean interaction in scaffold system tests.
Gannon McGibbon
v5.2.2.1
Compare Source
v5.2.2
: 5.2.2Compare Source
Active Support
Fix bug where
#to_options
forActiveSupport::HashWithIndifferentAccess
would not act as alias for
#symbolize_keys
.Nick Weiland
Improve the logic that detects non-autoloaded constants.
Jan Habermann, Xavier Noria
Fix bug where
URI.unescape
would fail with mixed Unicode/escaped character input:Ashe Connor, Aaron Patterson
Active Model
Fix numericality validator to still use value before type cast except Active Record.
Fixes #33651, #33686.
Ryuta Kamizono
Active Record
Do not ignore the scoping with query methods in the scope block.
Ryuta Kamizono
Allow aliased attributes to be used in
#update_columns
and#update
.Gannon McGibbon
Allow spaces in postgres table names.
Fixes issue where "user post" is misinterpreted as ""user"."post"" when quoting table names with the postgres
adapter.
Gannon McGibbon
Cached columns_hash fields should be excluded from ResultSet#column_types
PR #34528 addresses the inconsistent behaviour when attribute is defined for an ignored column. The following test
was passing for SQLite and MySQL, but failed for PostgreSQL:
Dmitry Tsepelev
Values of enum are frozen, raising an error when attempting to modify them.
Emmanuel Byrd
update_columns
now correctly raisesActiveModel::MissingAttributeError
if the attribute does not exist.
Sean Griffin
Do not use prepared statement in queries that have a large number of binds.
Ryuta Kamizono
Fix query cache to load before first request.
Eileen M. Uchitelle
Fix collection cache key with limit and custom select to avoid ambiguous timestamp column error.
Fixes #33056.
Federico Martinez
Fix duplicated record creation when using nested attributes with
create_with
.Darwin Wu
Fix regression setting children record in parent
before_save
callback.Guo Xiang Tan
Prevent leaking of user's DB credentials on
rails db:create
failure.bogdanvlviv
Clear mutation tracker before continuing the around callbacks.
Yuya Tanaka
Prevent deadlocks when waiting for connection from pool.
Brent Wheeldon
Avoid extra scoping when using
Relation#update
that was causing this method to change the current scope.Ryuta Kamizono
Fix numericality validator not to be affected by custom getter.
Ryuta Kamizono
Fix bulk change table ignores comment option on PostgreSQL.
Yoshiyuki Kinjo
Action View
Action Pack
Reset Capybara sessions if failed system test screenshot raising an exception.
Reset Capybara sessions if
take_failed_screenshot
raise exceptionin system test
after_teardown
.Maxim Perepelitsa
Use request object for context if there's no controller
There is no controller instance when using a redirect route or a
mounted rack application so pass the request object as the context
when resolving dynamic CSP sources in this scenario.
Fixes #34200.
Andrew White
Apply mapping to symbols returned from dynamic CSP sources
Previously if a dynamic source returned a symbol such as :self it
would be converted to a string implicity, e.g:
would generate the header:
and now it generates:
Andrew White
Fix
rails routes -c
for controller name consists of multiple word.Yoshiyuki Kinjo
Call the
#redirect_to
block in controller context.Steven Peckins
Active Job
Make sure
assert_enqueued_with()
&assert_performed_with()
work reliably with hash arguments.Sharang Dashputre
Restore
ActionController::Parameters
support toActiveJob::Arguments.serialize
.Bernie Chiu
Restore
HashWithIndifferentAccess
support toActiveJob::Arguments.deserialize
.Gannon McGibbon
Include deserialized arguments in job instances returned from
assert_enqueued_with
andassert_performed_with
Alan Wu
Increment execution count before deserialize arguments.
Currently, the execution count increments after deserializes arguments.
Therefore, if an error occurs with deserialize, it retries indefinitely.
Yuji Yaginuma
Action Mailer
Action Cable
Active Storage
Support multiple submit buttons in Active Storage forms.
Chrıs Seelus
Fix
ArgumentError
when uploading to amazon s3Hiroki Sanpei
Add a foreign-key constraint to the
active_storage_attachments
table for blobs.George Claghorn
Discard
ActiveStorage::PurgeJobs
for missing blobs.George Claghorn
Fix uploading Tempfiles to Azure Storage.
George Claghorn
Railties
Disable content security policy for mailer previews.
Dylan Reile
Log the remote IP address of clients behind a proxy.
Atul Bhosale
v5.2.1.1
Compare Source
v5.2.1
Compare Source
v5.2.0
Compare Source
v5.1.7
: 5.1.7Compare Source
Active Support
Active Model
Active Record
Fix
touch
option to behave consistently withPersistence#touch
method.Ryuta Kamizono
Back port Rails 5.2
reverse_order
Arel SQL literal fix.Matt Jones, Brooke Kuhlmann
becomes
should clear the mutation tracker which is created inafter_initialize
.Fixes #32867.
Ryuta Kamizono
Action View
Fix issue with
button_to
'sto_form_params
button_to
was throwing exception when invoked withparams
hash thatcontains symbol and string keys. The reason for the exception was that
to_form_params
was comparing the given symbol and string keys.The issue is fixed by turning all keys to strings inside
to_form_params
before comparing them.Georgi Georgiev
Action Pack
Active Job
Action Mailer
Action Cable
Railties
v5.1.6.2
Compare Source
v5.1.6.1
Compare Source
v5.1.6
Compare Source
v5.1.5
Compare Source
v5.1.4
Compare Source
v5.1.3
Compare Source
v5.1.2
Compare Source
v5.1.1
Compare Source
v5.1.0
Compare Source
v5.0.7.2
Compare Source
v5.0.7.1
Compare Source
v5.0.7
Compare Source
v5.0.6
Compare Source
v5.0.5
Compare Source
v5.0.4
Compare Source
v5.0.3
Compare Source
v5.0.2
Compare Source
v5.0.1
Compare Source
v5.0.0.1
Compare Source
v5.0.0
Compare Source
v4.2.11.3
: 4.2.11.3Compare Source
Action Mailer
Action Pack
Action View
Active Job
Active Model
Active Record
Active Support
Railties
v4.2.11.2
: 4.2.11.2Compare Source
Action Mailer
Action Pack
Action View
Active Job
Active Model
Active Record
Active Support
Railties
v4.2.11.1
Compare Source
v4.2.11
Compare Source
v4.2.10
Compare Source
v4.2.9
Compare Source
v4.2.8
Compare Source
v4.2.7.1
Compare Source
v4.2.7
Compare Source
v4.2.6
Compare Source
v4.2.5.2
Compare Source
v4.2.5.1
Compare Source
v4.2.5
Compare Source
v4.2.4
Compare Source
v4.2.3
Compare Source
v4.2.2
Compare Source
v4.2.1
Compare Source
v4.2.0
Compare Source
v4.1.16
Compare Source
v4.1.15
Compare Source
v4.1.14.2
Compare Source
v4.1.14.1
Compare Source
v4.1.14
Compare Source
v4.1.13
Compare Source
v4.1.12
Compare Source
v4.1.11
Compare Source
v4.1.10
Compare Source
v4.1.9
Compare Source
v4.1.8
Compare Source
v4.1.7.1
Compare Source
v4.1.7
Compare Source
v4.1.6
Compare Source
v4.1.5
Compare Source
v4.1.4
Compare Source
v4.1.3
Compare Source
v4.1.2
Compare Source
v4.1.1
Compare Source
v4.1.0
Compare Source
v4.0.13
Compare Source
v4.0.12
Compare Source
v4.0.11.1
Compare Source
v4.0.11
Compare Source
v4.0.10
Compare Source
v4.0.9
Compare Source
v4.0.8
Compare Source
v4.0.7
Compare Source
v4.0.6
Compare Source
v4.0.5
Compare Source
v4.0.4
Compare Source
v4.0.3
Compare Source
v4.0.2
Compare Source
v4.0.1
Compare Source
v4.0.0
Compare Source
v3.2.22.5
Compare Source
v3.2.22.4
Compare Source
v3.2.22.3
Compare Source
v3.2.22.2
Compare Source
v3.2.22.1
Compare Source
v3.2.22
Compare Source
v3.2.21
Compare Source
v3.2.20
Compare Source
v3.2.19
Compare Source
v3.2.18
Compare Source
v3.2.17
Compare Source
v3.2.16
Compare Source
v3.2.15
Compare Source
v3.2.14
Compare Source
v3.2.13
Compare Source
v3.2.12
Compare Source
v3.2.11
Compare Source
v3.2.10
Compare Source
v3.2.9
Compare Source
v3.2.8
Compare Source
v3.2.7
Compare Source
v3.2.6
Compare Source
v3.2.5
Compare Source
v3.2.4
Compare Source
v3.2.3
Compare Source
v3.2.2
Compare Source
v3.2.1
Compare Source
v3.2.0
Compare Source
v3.1.12
Compare Source
v3.1.11
Compare Source
v3.1.10
Compare Source
v3.1.9
Compare Source
v3.1.8
Compare Source
v3.1.7
Compare Source
v3.1.6
Compare Source
v3.1.5
Compare Source
v3.1.4
Compare Source
v3.1.3
Compare Source
v3.1.2
Compare Source
v3.1.1
Compare Source
v3.1.0
Compare Source
v3.0.20
Compare Source
v3.0.19
Compare Source
v3.0.18
Compare Source
v3.0.17
Compare Source
v3.0.16
Compare Source
v3.0.15
Compare Source
v3.0.14
Compare Source
v3.0.13
Compare Source
v3.0.12
Compare Source
v3.0.11
Compare Source
v3.0.10
Compare Source
v3.0.9
Compare Source
v3.0.8
Compare Source