-
Notifications
You must be signed in to change notification settings - Fork 18
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
sgupta/upgrade rails to 6.1.7.7 #11
Open
shubhiguptaa
wants to merge
72
commits into
ebrynne:master
Choose a base branch
from
Hacker0x01:sgupta/upgrade_rails_to_6.1.7.7
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
sgupta/upgrade rails to 6.1.7.7 #11
shubhiguptaa
wants to merge
72
commits into
ebrynne:master
from
Hacker0x01:sgupta/upgrade_rails_to_6.1.7.7
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Merge hackday improvements into our company fork
Extension updates from my own repo
It feels odd when saving a new link. The Save button should be on the right side of the form: this fixes that.
Locate Save button on logical side
Bumps [sprockets](http://getsprockets.org/) from 3.7.1 to 3.7.2. Signed-off-by: dependabot[bot] <support@github.com>
Bumps [nokogiri](https://github.com/sparklemotion/nokogiri) from 1.8.1 to 1.10.4. - [Release notes](https://github.com/sparklemotion/nokogiri/releases) - [Changelog](https://github.com/sparklemotion/nokogiri/blob/master/CHANGELOG.md) - [Commits](sparklemotion/nokogiri@v1.8.1...v1.10.4) Signed-off-by: dependabot[bot] <support@github.com>
Bumps [bootstrap-sass](https://github.com/twbs/bootstrap-sass) from 3.3.7 to 3.4.1. - [Release notes](https://github.com/twbs/bootstrap-sass/releases) - [Changelog](https://github.com/twbs/bootstrap-sass/blob/master/CHANGELOG.md) - [Commits](twbs/bootstrap-sass@v3.3.7...v3.4.1) Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rack](https://github.com/rack/rack) from 2.0.3 to 2.0.7. - [Release notes](https://github.com/rack/rack/releases) - [Changelog](https://github.com/rack/rack/blob/master/CHANGELOG.md) - [Commits](rack/rack@2.0.3...2.0.7) Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ffi](https://github.com/ffi/ffi) from 1.9.18 to 1.11.1. - [Release notes](https://github.com/ffi/ffi/releases) - [Changelog](https://github.com/ffi/ffi/blob/master/CHANGELOG.md) - [Commits](ffi/ffi@1.9.18...1.11.1) Signed-off-by: dependabot[bot] <support@github.com>
Bump sprockets from 3.7.1 to 3.7.2
Bump nokogiri from 1.8.1 to 1.10.4
…ass-3.4.1 Bump bootstrap-sass from 3.3.7 to 3.4.1
Bump rack from 2.0.3 to 2.0.7
Bump ffi from 1.9.18 to 1.11.1
Bumps [loofah](https://github.com/flavorjones/loofah) from 2.1.1 to 2.2.3. - [Release notes](https://github.com/flavorjones/loofah/releases) - [Changelog](https://github.com/flavorjones/loofah/blob/master/CHANGELOG.md) - [Commits](flavorjones/loofah@v2.1.1...v2.2.3) Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rails-html-sanitizer](https://github.com/rails/rails-html-sanitizer) from 1.0.3 to 1.2.0. - [Release notes](https://github.com/rails/rails-html-sanitizer/releases) - [Changelog](https://github.com/rails/rails-html-sanitizer/blob/master/CHANGELOG.md) - [Commits](rails/rails-html-sanitizer@v1.0.3...v1.2.0) Signed-off-by: dependabot[bot] <support@github.com>
Bump loofah from 2.1.1 to 2.2.3
…anitizer-1.2.0 Bump rails-html-sanitizer from 1.0.3 to 1.2.0
Bumps [loofah](https://github.com/flavorjones/loofah) from 2.2.3 to 2.3.1. - [Release notes](https://github.com/flavorjones/loofah/releases) - [Changelog](https://github.com/flavorjones/loofah/blob/master/CHANGELOG.md) - [Commits](flavorjones/loofah@v2.2.3...v2.3.1) Signed-off-by: dependabot[bot] <support@github.com>
Bump loofah from 2.2.3 to 2.3.1
Bumps [rack-cors](https://github.com/cyu/rack-cors) from 1.0.3 to 1.0.5. - [Release notes](https://github.com/cyu/rack-cors/releases) - [Changelog](https://github.com/cyu/rack-cors/blob/master/CHANGELOG.md) - [Commits](cyu/rack-cors@v1.0.3...v1.0.5) Signed-off-by: dependabot[bot] <support@github.com>
….0.5 Bump rack-cors from 1.0.3 to 1.0.5
Bumps [rack](https://github.com/rack/rack) from 2.0.7 to 2.0.8. - [Release notes](https://github.com/rack/rack/releases) - [Changelog](https://github.com/rack/rack/blob/master/CHANGELOG.md) - [Commits](rack/rack@2.0.7...2.0.8) Signed-off-by: dependabot[bot] <support@github.com>
Bump rack from 2.0.7 to 2.0.8
Bumps [puma](https://github.com/puma/puma) from 4.3.0 to 4.3.1. - [Release notes](https://github.com/puma/puma/releases) - [Changelog](https://github.com/puma/puma/blob/master/History.md) - [Commits](puma/puma@v4.3.0...v4.3.1) Signed-off-by: dependabot[bot] <support@github.com>
Bump puma from 4.3.0 to 4.3.1
Bumps [nokogiri](https://github.com/sparklemotion/nokogiri) from 1.10.5 to 1.10.8. - [Release notes](https://github.com/sparklemotion/nokogiri/releases) - [Changelog](https://github.com/sparklemotion/nokogiri/blob/master/CHANGELOG.md) - [Commits](sparklemotion/nokogiri@v1.10.5...v1.10.8) Signed-off-by: dependabot[bot] <support@github.com>
…10.8 Bump nokogiri from 1.10.5 to 1.10.8
Bumps [puma](https://github.com/puma/puma) from 4.3.1 to 4.3.3. - [Release notes](https://github.com/puma/puma/releases) - [Changelog](https://github.com/puma/puma/blob/master/History.md) - [Commits](puma/puma@v4.3.1...v4.3.3) Signed-off-by: dependabot[bot] <support@github.com>
Support libv8 on linux
Serve digest version of assets
Update mimemagic to 0.3.10 version
Bumps [puma](https://github.com/puma/puma) from 5.2.2 to 5.3.1. - [Release notes](https://github.com/puma/puma/releases) - [Changelog](https://github.com/puma/puma/blob/master/History.md) - [Commits](puma/puma@v5.2.2...v5.3.1) Signed-off-by: dependabot[bot] <support@github.com>
Bump puma from 5.2.2 to 5.3.1
Bumps [puma](https://github.com/puma/puma) from 5.3.1 to 5.6.4. - [Release notes](https://github.com/puma/puma/releases) - [Changelog](https://github.com/puma/puma/blob/master/History.md) - [Commits](puma/puma@v5.3.1...v5.6.4) --- updated-dependencies: - dependency-name: puma dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rack](https://github.com/rack/rack) from 2.2.3 to 2.2.3.1. - [Release notes](https://github.com/rack/rack/releases) - [Changelog](https://github.com/rack/rack/blob/main/CHANGELOG.md) - [Commits](rack/rack@2.2.3...2.2.3.1) --- updated-dependencies: - dependency-name: rack dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bump puma from 5.3.1 to 5.6.4
Bump rack from 2.2.3 to 2.2.3.1
Upgrading for Ruby 3.2 Compatibility
Adding missing package.json
upgrade rails + rack
Upgrade rails to 6.1.7.4
Upgrade Rails to 6.1.7.4
Add missing app/assets/config/manifest.js
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR is to fix the following:
There is a possible sensitive session information leak in Active Storage. This vulnerability has been assigned the CVE identifier CVE-2024-26144.
Versions Affected: >= 5.2.0, < 7.1.0 Not affected: < 5.2.0, >= 7.1.0 Fixed Versions: 7.0.8.1, 6.1.7.7
More details:
https://discuss.rubyonrails.org/t/possible-sensitive-session-information-leak-in-active-storage/84945
Rails has also announced possible denial of service security vulnerabilities in the content type parsing component of Rack, in the header parsing routines, and range header in rack, this is affecting the version of rack we are using. CVE-2024-25126, CVE-2024-26146 and CVE-2024-26141
The vulnerability was fixed in the versions: 2.2.8.1, 3.0.9.1
Read more :
https://discuss.rubyonrails.org/t/denial-of-service-vulnerability-in-rack-content-type-parsing/84941 https://discuss.rubyonrails.org/t/possible-denial-of-service-vulnerability-in-rack-header-parsing/84942 https://discuss.rubyonrails.org/t/possible-dos-vulnerability-with-range-header-in-rack/84944/1