Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🚨 [security] Update rails 7.0.8.6 → 7.0.8.7 (patch) #879

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from

Conversation

depfu[bot]
Copy link
Contributor

@depfu depfu bot commented Dec 11, 2024


🚨 Your current dependencies have known security vulnerabilities 🚨

This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!


Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.

What changed?

✳️ rails (7.0.8.6 → 7.0.8.7) · Repo

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ actioncable (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Release Notes

7.0.8.7 (from changelog)

  • No changes.

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ actionmailbox (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

↗️ actionmailer (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Release Notes

7.0.8.7 (from changelog)

  • No changes.

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ actionpack (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Security Advisories 🚨

🚨 Possible Content Security Policy bypass in Action Dispatch

There is a possible Cross Site Scripting (XSS) vulnerability in the content_security_policy helper in Action Pack.

Impact

Applications which set Content-Security-Policy (CSP) headers dynamically from untrusted user input may be vulnerable to carefully crafted inputs being able to inject new directives into the CSP. This could lead to a bypass of the CSP and its protection against XSS and other attacks.

Releases

The fixed releases are available at the normal locations.

Workarounds

Applications can avoid setting CSP headers dynamically from untrusted input, or can validate/sanitize that input.

Credits

Thanks to ryotak for the report!

Release Notes

7.0.8.7 (from changelog)

  • Add validation to content security policies to disallow spaces and semicolons. Developers should use multiple arguments, and different directive methods instead.

    [CVE-2024-54133]

    Gannon McGibbon

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ actiontext (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Release Notes

7.0.8.7 (from changelog)

  • Update vendored trix version to 1.3.4

    John Hawthorn

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ actionview (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Release Notes

7.0.8.7 (from changelog)

  • No changes.

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ activejob (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Release Notes

7.0.8.7 (from changelog)

  • No changes.

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ activemodel (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Release Notes

7.0.8.7 (from changelog)

  • No changes.

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ activerecord (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Release Notes

7.0.8.7 (from changelog)

  • No changes.

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ activestorage (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Release Notes

7.0.8.7 (from changelog)

  • No changes.

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ activesupport (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Release Notes

7.0.8.7 (from changelog)

  • No changes.

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ date (indirect, 3.3.4 → 3.4.1) · Repo

Release Notes

3.4.1

What's Changed

  • Fix incorrect argc2 decrement in datetime_s_iso8601 function by @pelbyl in #105
  • Trivial changes by @nobu in #107
  • Bump step-security/harden-runner from 2.10.1 to 2.10.2 by @dependabot in #109
  • Bump rubygems/release-gem from 612653d273a73bdae1df8453e090060bb4db5f31 to 9e85cb11501bebc2ae661c1500176316d3987059 by @dependabot in #108
  • [DOC] Empty the false document by @nobu in #110
  • Suppress warnings by @nobu in #111

New Contributors

Full Changelog: v3.4.0...v3.4.1

3.4.0

What's Changed

  • Provide a 'Changelog' link on rubygems.org/gems/date by @mark-young-atg in #101
  • Remove the unintentional ability to parse Symbol by @nobu in #102
  • Prevent converted gregorian date from GC by @nobu in #103
  • [DOC] Specify the unit of return value for Date#- by @p0pemaru in #97
  • Update gperf by @nobu in #104

New Contributors

Full Changelog: v3.3.4...v3.4.0

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 35 commits:

↗️ minitest (indirect, 5.25.2 → 5.25.4) · Repo · Changelog

Release Notes

5.25.4 (from changelog)

  • 1 bug fix:

    • Fix for must_verify definition if only requiring minitest/mock (but why?).

5.25.3 (from changelog)

  • 5 bug fixes:

    • Fixed assert_mock to fail instead of raise on unmet mock expectations.

    • Fixed assert_mock to take an optional message argument.

    • Fixed formatting of unmet mock expectation messages.

    • Fixed missing must_verify expectation to match assert_mock.

    • minitest/pride: Fixed to use true colors with *-direct terminals (bk2204)

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 5 commits:

↗️ net-imap (indirect, 0.5.0 → 0.5.1) · Repo

Release Notes

0.5.1

What's Changed

Added

  • ✨ Add SequenceSet#deconstruct by @nevans in #343
  • ✨ Coerce Set, :*, #to_sequence_set search args into sequence-set by @nevans in #351
  • ✨ Enable parenthesized lists in search criteria by @nevans in #345

Fixed

  • 🐛 Ensure set is loaded in ruby 3.1 by @nevans in #342
  • 🐛 Fix SequenceSet.try_convert by @nevans in #349

Documentation

Other Changes

  • ♻️ Reduce duplication in normalizing search args by @nevans in #348

Miscellaneous

  • Make simplecov-json as optional dependency by @hsbt in #344
  • Removed needless workaround by @hsbt in #346

Full Changelog: v0.5.0...v0.5.1

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 26 commits:

↗️ nokogiri (indirect, 1.17.0 → 1.17.1) · Repo · Changelog

Release Notes

1.17.1

v1.17.1 / 2024-12-10

Fixed

  • Fixed a potential segfault when using Node#dup and DocumentFragment#dup. [#3359] @byroot @flavorjones
  • Node#dup and Node#clone now correctly decorate the new node with the document's Node decorators. [#3363] @flavorjones

sha256 checksums

b3fce09bddfab61ae587f83af97bf0d0834352bcd23ad99831f2993d978627bd  nokogiri-1.17.1-aarch64-linux.gem
0e79badf832783e81439c3211562ed904a5c8eaaa0038c8fdfdb3778e873f3d0  nokogiri-1.17.1-arm64-darwin.gem
b8e9909ff893b257a58066e6bfc39456be18b87f4af1e22ca18d7c0dbc9925e5  nokogiri-1.17.1-arm-linux.gem
910fe0f194db99677f7ddb21b19a1d071ceffc4a0e39d44c08736d9b1e558cfc  nokogiri-1.17.1.gem
baf2cf6785f83c8cb3cdc427d0eb8b7f91d76748bfeb6c2612ce639e82c1ecee  nokogiri-1.17.1-java.gem
601a8bca523bf2b1a576c728ad4901c57263d0c29e4f9e6d2abe654c6a929841  nokogiri-1.17.1-x64-mingw32.gem
299ab9cd2c4ce882112e79fc31f82915920cb3e54ba526287e86d9a5fbfafebe  nokogiri-1.17.1-x64-mingw-ucrt.gem
94bcacacd123379229a8ece0d31c38af36d0ef6f86f399d5813be5ca0f566c88  nokogiri-1.17.1-x86_64-darwin.gem
2234250605b03433747e8d21de947b38b79f33a4280930e58bec179fd95d415d  nokogiri-1.17.1-x86_64-linux.gem
d09565316ffc8f8bb522bd6d1b460dec2a57d23d6e479c2d0d49d9ccbb11076c  nokogiri-1.17.1-x86-linux.gem
8f720dd62bf5d3791aa67f933085be5d2a2ab06afc120d4f210f40a5d184fafb  nokogiri-1.17.1-x86-mingw32.gem

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 5 commits:

↗️ railties (indirect, 7.0.8.6 → 7.0.8.7) · Repo · Changelog

Release Notes

7.0.8.7 (from changelog)

  • No changes.

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 3 commits:

↗️ timeout (indirect, 0.4.1 → 0.4.2) · Repo

Release Notes

0.4.2

What's Changed

  • fixed check for error bubble up test by @jjb in #43
  • [DOC] Missing documents by @nobu in #45
  • Provide a 'Changelog' link on rubygems.org/gems/timeout by @mark-young-atg in #46
  • Global #timeout was removed 5 years ago by @jpcamara in #49
  • timeout.rb: Update documentation to match README by @olleolleolle in #50

New Contributors

Full Changelog: v0.4.1...v0.4.2

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by 15 commits:


Depfu Status

Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with @depfu rebase.

All Depfu comment commands
@​depfu rebase
Rebases against your default branch and redoes this update
@​depfu recreate
Recreates this PR, overwriting any edits that you've made to it
@​depfu merge
Merges this PR once your tests are passing and conflicts are resolved
@​depfu cancel merge
Cancels automatic merging of this PR
@​depfu close
Closes this PR and deletes the branch
@​depfu reopen
Restores the branch and reopens this PR (if it's closed)
@​depfu pause
Ignores all future updates for this dependency and closes this PR
@​depfu pause [minor|major]
Ignores all future minor/major updates for this dependency and closes this PR
@​depfu resume
Future versions of this dependency will create PRs again (leaves this PR as is)

@depfu depfu bot added dependencies Pull requests that update a dependency file Technical debt Technical debt labels Dec 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file Technical debt Technical debt
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants