Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with
or
.
Download ZIP
Commits on Jul 26, 2012
  1. @tenderlove

    bumping to 3.0.16

    tenderlove authored
  2. @tenderlove

    updating release date

    tenderlove authored
  3. @tenderlove

    updating changelog with CVE

    tenderlove authored
  4. @tenderlove
Commits on Jul 23, 2012
  1. @tenderlove

    updating changelogs

    tenderlove authored
Commits on Jun 13, 2012
  1. @tenderlove

    3.0.15

    tenderlove authored
Commits on Jun 12, 2012
  1. @tenderlove

    updating changelogs

    tenderlove authored
Commits on Jun 11, 2012
  1. @tenderlove

    bumping to 3.0.14

    tenderlove authored
  2. @tenderlove
  3. @tenderlove
  4. @tenderlove
Commits on May 31, 2012
  1. @tenderlove

    bumping to 3.0.13

    tenderlove authored
  2. @tenderlove

    updating CHANGELOGs

    tenderlove authored
  3. @tenderlove

    Merge branch '3-0-stable-sec' into 3-0-rel

    tenderlove authored
    * 3-0-stable-sec:
      Strip [nil] from parameters hash. Thanks to Ben Murphy for reporting this!
      predicate builder should not recurse for determining where columns. Thanks to Ben Murphy for reporting this
Commits on May 30, 2012
  1. @tenderlove

    Strip [nil] from parameters hash.

    tenderlove authored
    Thanks to Ben Murphy for reporting this!
    
    CVE-2012-2660
    
    Conflicts:
    
    	actionpack/lib/action_dispatch/http/request.rb
Commits on May 28, 2012
  1. @tenderlove

    bumping to 3.0.13.rc1

    tenderlove authored
Commits on May 27, 2012
  1. @rafaelfranca
Commits on May 26, 2012
  1. @homakov

    do not force sanitize and whitelist protocols for auto_link

    homakov authored
    sanitize is not always required so we cannot make it. let's just
    whitelist protocols
Commits on May 25, 2012
  1. @homakov

    auto_link final sanitize

    homakov authored
Commits on Mar 27, 2012
  1. @tenderlove

    Merge pull request #5613 from carlosantoniodasilva/fix-build-3-0-193

    tenderlove authored
    Fix build for branch 3-0-stable - Ruby 1.9.3
  2. @josevalim @drogus

    Avoid inspecting the whole route set, closes #1525

    josevalim authored drogus committed
  3. @arunagw @carlosantoniodasilva

    Fix broken encoding test

    arunagw authored carlosantoniodasilva committed
  4. @tenderlove @carlosantoniodasilva
  5. @miloops @carlosantoniodasilva

    Use helper method here.

    miloops authored carlosantoniodasilva committed
  6. @miloops @carlosantoniodasilva
Commits on Mar 26, 2012
  1. @carlosantoniodasilva

    Fix AV::FixtureResolver and rjs tests with random order errors

    carlosantoniodasilva authored
    Due to the hash ordering changes on Ruby 1.8.7-p358.
Commits on Mar 24, 2012
  1. @arunagw @carlosantoniodasilva
Commits on Mar 15, 2012
  1. @tenderlove

    Merge pull request #5457 from brianmario/typo-fix

    tenderlove authored
    Fix typo in redirect test
  2. @tenderlove

    Merge pull request #5456 from brianmario/redirect-sanitization

    tenderlove authored
    Strip null bytes from Location header
    Conflicts:
    
    	actionpack/test/controller/redirect_test.rb
Commits on Mar 7, 2012
  1. @arunagw
Commits on Mar 1, 2012
  1. @tenderlove

    bumping to 3.0.12

    tenderlove authored
  2. @tenderlove

    Merge branch '3-0-stable-security' into 3-0-12

    tenderlove authored
    * 3-0-stable-security:
      Ensure [] respects the status of the buffer.
      use AS::SafeBuffer#clone_empty for flushing the output_buffer
      add AS::SafeBuffer#clone_empty
      fix output safety issue with select options
Commits on Feb 22, 2012
  1. @tenderlove

    updating RAILS_VERSION

    tenderlove authored
  2. @jonleighton
Commits on Feb 21, 2012
  1. @amatsuda @tenderlove
Something went wrong with that request. Please try again.