vuejs-rails-starterkit icon indicating copy to clipboard operation
vuejs-rails-starterkit copied to clipboard

Bump addressable from 2.7.0 to 2.8.1

Open dependabot[bot] opened this issue 3 years ago • 0 comments

Bumps addressable from 2.7.0 to 2.8.1.

Changelog

Sourced from addressable's changelog.

Addressable 2.8.1

  • refactor Addressable::URI.normalize_path to address linter offenses (#430)
  • remove redundant colon in Addressable::URI::CharacterClasses::AUTHORITY regex (#438)
  • update gemspec to reflect supported Ruby versions (#466, #464, #463)
  • compatibility w/ public_suffix 5.x (#466, #465, #460)
  • fixes "invalid byte sequence in UTF-8" exception when unencoding URLs containing non UTF-8 characters (#459)
  • Ractor compatibility (#449)
  • use the whole string instead of a single line for template match (#431)
  • force UTF-8 encoding only if needed (#341)

#460: sporkmonger/addressable#460 #463: sporkmonger/addressable#463 #464: sporkmonger/addressable#464 #465: sporkmonger/addressable#465 #466: sporkmonger/addressable#466

Addressable 2.8.0

  • fixes ReDoS vulnerability in Addressable::Template#match
  • no longer replaces + with spaces in queries for non-http(s) schemes
  • fixed encoding ipv6 literals
  • the :compacted flag for normalized_query now dedupes parameters
  • fix broken escape_component alias
  • dropping support for Ruby 2.0 and 2.1
  • adding Ruby 3.0 compatibility for development tasks
  • drop support for rack-mount and remove Addressable::Template#generate
  • performance improvements
  • switch CI/CD to GitHub Actions
Commits
  • 8657465 Update version, gemspec, and CHANGELOG for 2.8.1 (#474)
  • 4fc5bb6 CI: remove Ubuntu 18.04 job (#473)
  • 860fede Force UTF-8 encoding only if needed (#341)
  • 99810af Merge pull request #431 from ojab/ct-_do_not_parse_multiline_strings
  • 7ce0f48 Merge branch 'main' into ct-_do_not_parse_multiline_strings
  • 7ecf751 Merge pull request #449 from okeeblow/freeze_concatenated_strings
  • 41f12dd Merge branch 'main' into freeze_concatenated_strings
  • 068f673 Merge pull request #459 from jarthod/iso-encoding-problem
  • b4c9882 Merge branch 'main' into iso-encoding-problem
  • 08d27e8 Merge pull request #471 from sporkmonger/sporkmonger-enable-codeql
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

dependabot[bot] avatar Aug 22 '22 10:08 dependabot[bot]