ruby-getting-started
ruby-getting-started copied to clipboard
Bump rails from 7.1.3.2 to 7.1.3.4
Bumps rails from 7.1.3.2 to 7.1.3.4.
Release notes
Sourced from rails's releases.
7.1.3.4
Active Support
- No changes.
Active Model
- No changes.
Active Record
- No changes.
Action View
- No changes.
Action Pack
- Include the HTTP Permissions-Policy on non-HTML Content-Types [CVE-2024-28103]
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
... (truncated)
Commits
19eebf6Preparing for 7.1.3.4 releasebd7c28aupdate changelog1ac6d40Sanitize ActionText HTML ContentAttachment in Trix edit viewc7b9e0cinclude the HTTP Permissions-Policy on non-HTML Content-Types747a03bPreparing for 7.1.3.3 release260cb39Upgrade Trix to 2.1.1 to fix [CVE-2024-34341][1]- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)