🚨 [security] Update all of rails: 6.1.4.1 → 6.1.6.1 (patch) #46
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ activerecord (6.1.4.1 → 6.1.6.1) · Repo · Changelog
Security Advisories 🚨
🚨 Possible RCE escalation bug with Serialized Columns in Active Record
Release Notes
6.1.5.1 (from changelog)
6.1.5 (from changelog)
6.1.4.7 (from changelog)
6.1.4.6 (from changelog)
6.1.4.5 (from changelog)
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
✳️ activesupport (6.1.4.1 → 6.1.6.1) · Repo · Changelog
Release Notes
6.1.5.1 (from changelog)
6.1.5 (from changelog)
6.1.4.7 (from changelog)
6.1.4.6 (from changelog)
6.1.4.5 (from changelog)
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
✳️ minitest (5.15.0 → 5.16.2) · Repo · Changelog
Release Notes
5.16.2 (from changelog)
5.16.1 (from changelog)
5.16.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 35 commits:
prepped for releaseCI: just show dots pleasehaha- Added MT_KWARGS_HACK kludge for stub to deal with ruby 2.7 kwargs nastiness. (tsugimoto)- Nuke ivars if exception fails to marshal twice (eg better_errors). (irphilli)- In #expect, pop Hash class from args if $MT_KWARGS_HACK. (casperisfine)prepped for release- Clarified some doco wrt the block on #stub.- Apparently adding real kwarg support to mocks/stubs broke some code. Fixed.! Dropping ruby 2.2 - 2.5. 2.6 is DTM soon too.prepped for releaseFixed a test that's broken if only 1 CPU (eg, my server... oops)- Had to patch up mock and stub to deal with <=2.7 kwargs odditiesFinally flushed out the last edge cases (that I can find) for mocks wrt kwargs.- Extended Mock#expect to record kwargs.oops... this part of the exception is only on ruby 3.1+- (Re)Fixed marshalling of exceptions, neutering them in 2 passes.refactored method checks into a custom assertion. (tenderlove)! Added Minitest::TestTask.Renamed Minitest::SEED to Minitest.seed+ Added --show-skips option to show skips at end of run but not require --verbose. (MSP-Greg)- Fixed more problems with rdoc.oops+ Added Minitest::SEED, the random seed used by the run.+ Removed minor optimization removing empty suites before run.+ assert_match now returns the MatchData on success. (Nakilon)Drop ruby 2.2-2.6 from CI now that rails 5.2 is EOL! YAY! Other simplifications as well.Drop windows from the CI matrix and run windows-latest + ruby-latest. It's SO slow and not really worth the extra effort.don't use bundler for either test tasksetup-ruby prints the versionBumped CI a fair amountAdded stubberry to readme. (alekseyl)Fixed random test failure because of parallel execution. (mame)Replaced http with https whenever such link exists. (apatniv)Updated the test suite to handle ASCII-8BIT renaming. (casperisfine)Release Notes
6.1.5.1 (from changelog)
6.1.5 (from changelog)
6.1.4.7 (from changelog)
6.1.4.6 (from changelog)
6.1.4.5 (from changelog)
6.1.4.4 (from changelog)
6.1.4.3 (from changelog)
6.1.4.2 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
1.1.10
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
1.11.0
1.10.0
1.9.1
1.9.0
1.8.11
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
2.6.0 (from changelog)
2.5.4 (from changelog)
2.5.3 (from changelog)
2.5.1 (from changelog)
2.5.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands