Bump actionpack from 7.0.2.3 to 7.0.4.2
Bumps actionpack from 7.0.2.3 to 7.0.4.2.
Release notes
Sourced from actionpack's releases.
v7.0.4.2
Active Support
- No changes.
Active Model
- No changes.
Active Record
- No changes.
Action View
- No changes.
Action Pack
Fix
domain: :allfor two letter TLDThis fixes a compatibility issue introduced in our previous security release when using
domain: :allwith a two letter but single level top level domain domain (like.ca, rather than.co.uk).Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
... (truncated)
Changelog
Sourced from actionpack's changelog.
Rails 7.0.4.2 (January 24, 2023)
Fix
domain: :allfor two letter TLDThis fixes a compatibility issue introduced in our previous security release when using
domain: :allwith a two letter but single level top level domain domain (like.ca, rather than.co.uk).Rails 7.0.4.1 (January 17, 2023)
Fix sec issue with _url_host_allowed?
Disallow certain strings from
_url_host_allowed?to avoid a redirect to malicious sites.[CVE-2023-22797]
Avoid regex backtracking on If-None-Match header
[CVE-2023-22795]
Use string#split instead of regex for domain parts
[CVE-2023-22792]
Rails 7.0.4 (September 09, 2022)
Prevent
ActionDispatch::ServerTimingfrom overwriting existing values inServer-Timing.Previously, if another middleware down the chain set
Server-Timingheader, it would overwritten byActionDispatch::ServerTiming.Jakub Malinowski
Rails 7.0.3.1 (July 12, 2022)
- No changes.
Rails 7.0.3 (May 09, 2022)
Allow relative redirects when
raise_on_open_redirectsis enabled.Tom Hughes
Fix
authenticate_with_http_basicto allow for missing password.
... (truncated)
Commits
7c70791Version 7.0.4.21d6de16Merge pull request #47087 from jhawthorn/cookie_domain23e0345Version 7.0.4.18d82687Avoid regex backtracking on If-None-Match headercd46b0eUse string#split instead of regex for domain partse50e26dFix sec issue with _url_host_allowed?8015c2cVersion 7.0.4f3c345eMerge pull request #45964 from jhawthorn/server_timing_safety4d25c64Merge pull request #45221 from jhawthorn/ac_params_eql_fix47cff40Format inline code [ci-skip]- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)