Skip to content
Commits on Jul 26, 2012
  1. @tenderlove

    bumping to 3.1.7

    tenderlove committed
  2. @tenderlove

    updating rails release date

    tenderlove committed
  3. @tenderlove

    updating changelog with CVE

    tenderlove committed
  4. @tenderlove
Commits on Jul 23, 2012
  1. @tenderlove

    updating changelog

    tenderlove committed
Commits on Jun 14, 2012
  1. @tenderlove

    adding a test for #6459

    tenderlove committed
  2. @fxn

    removes item in the Active Record CHANGELOG

    fxn committed
    That change to update_attribute was considered
    to be too subtle and was reverted in 30ea923
    just before Rails 3 shipped. Later we introduced
    update_column (Rails 3.1).
Commits on Jun 12, 2012
  1. @tenderlove

    updating changelogs

    tenderlove committed
Commits on Jun 11, 2012
  1. @tenderlove

    bumping version numbers

    tenderlove committed
  2. @tenderlove
  3. @tenderlove
  4. @tenderlove

    Merge branch '3-1-stable-sec' into 3-1-stable-rel

    tenderlove committed
    * 3-1-stable-sec:
      Array parameters should not contain nil values.
      Additional fix for CVE-2012-2661
  5. @rafaelfranca
  6. @kennyj @tenderlove

    Change the string to use in test case.

    kennyj committed with tenderlove
    Conflicts:
    
    	activerecord/test/cases/adapters/mysql/mysql_adapter_test.rb
    	activerecord/test/cases/adapters/mysql2/schema_test.rb
  7. @kennyj @tenderlove

    Fix GH #3163. Should quote database on mysql/mysql2.

    kennyj committed with tenderlove
    Conflicts:
    
    	activerecord/test/cases/adapters/mysql/mysql_adapter_test.rb
    
    Conflicts:
    
    	activerecord/lib/active_record/connection_adapters/abstract_mysql_adapter.rb
    	activerecord/test/cases/adapters/mysql/mysql_adapter_test.rb
  8. @tenderlove
Commits on Jun 8, 2012
  1. @ernie @tenderlove

    Additional fix for CVE-2012-2661

    ernie committed with tenderlove
    While the patched PredicateBuilder in 3.1.5 prevents a user
    from specifying a table name using the `table.column` format,
    it doesn't protect against the nesting of hashes changing the
    table context in the next call to build_from_hash. This fix
    covers this case as well.
Commits on May 31, 2012
  1. @tenderlove

    Merge branch '3-1-rel' into 3-1-stable

    tenderlove committed
    * 3-1-rel:
      bumping to 3.1.5
      updating the CHANGELOG
      bumping to 3.1.5.rc1
  2. @tenderlove

    Merge branch '3-1-stable-sec' into 3-1-stable

    tenderlove committed
    * 3-1-stable-sec:
      Strip [nil] from parameters hash. Thanks to Ben Murphy for reporting this!
      predicate builder should not recurse for determining where columns. Thanks to Ben Murphy for reporting this
  3. @tenderlove

    bumping to 3.1.5

    tenderlove committed
  4. @tenderlove

    updating the CHANGELOG

    tenderlove committed
  5. @tenderlove

    Merge branch '3-1-stable-sec' into 3-1-rel

    tenderlove committed
    * 3-1-stable-sec:
      Strip [nil] from parameters hash. Thanks to Ben Murphy for reporting this!
      predicate builder should not recurse for determining where columns. Thanks to Ben Murphy for reporting this
Commits on May 30, 2012
  1. @tenderlove

    Strip [nil] from parameters hash.

    tenderlove committed
    Thanks to Ben Murphy for reporting this!
    
    CVE-2012-2660
  2. @tenderlove

    predicate builder should not recurse for determining where columns.

    tenderlove committed
    Thanks to Ben Murphy for reporting this
    
    CVE-2012-2661
Commits on May 29, 2012
  1. @rafaelfranca

    Merge pull request #6532 from freerange/3-1-stable-minitest-passthrou…

    rafaelfranca committed
    …gh-exceptions
    
    Exceptions like Interrupt should not be rescued in tests.
  2. @floehopper

    Exceptions like Interrupt should not be rescued in tests.

    floehopper committed
    This is a back-port of rails/rails#6525. See the commit notes there for
    details.
Commits on May 28, 2012
  1. @tenderlove

    bumping to 3.1.5.rc1

    tenderlove committed
Commits on May 13, 2012
  1. @rafaelfranca

    Merge pull request #3237 from sakuro/data-url-scheme

    rafaelfranca committed
    Support data: url scheme
  2. @spastorino

    Merge pull request #6300 from guilleiguaran/upgrade-sprockets-3-1-stable

    spastorino committed
    Upgrade sprockets to 2.0.4
  3. @guilleiguaran

    Upgrade sprockets to 2.0.4

    guilleiguaran committed
Commits on May 11, 2012
  1. @spastorino

    Merge pull request #6263 from arunagw/3-1-stable

    spastorino committed
    3 1 stable
  2. @arunagw
  3. @drogus

    Merge pull request #6261 from carlosantoniodasilva/fix-build-3-1

    drogus committed
    Fix build 3-1-stable
  4. @carlosantoniodasilva
Commits on May 10, 2012
  1. @pixeltrix
Something went wrong with that request. Please try again.