uuid
uuid copied to clipboard
Bump yard from 0.6.7 to 0.9.20
Bumps yard from 0.6.7 to 0.9.20.
Release notes
Sourced from yard's releases.
Release v0.9.20
- Fix parsing of stringified Symbols in Ruby source (#1256).
- Fix path traversal vulnerability in
yard server
. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of ayard server
host under certain conditions. Thanks to CuongMX from Viettel Cyber Security for discovering this vulnerability.Release v0.9.19
- Fixed bug in browser back button (#1071, #1228)
- Fixed handling of ArgumentError in ExtraFileObject (#1198)
- Fixed double return tag displaying on boolean methods (#1226)
- Removed unused
Module#namespace_name
function (#1229)- Fixed parsing order of README files. YARD will now prefer README over README.md over README.x.md or README-x.md (and the like). READMEs will now also be ordered by filename; the first README is still chosen unless
--readme
is provided.- Updated AsciiDoc markup support to use non-deprecated calls.
v0.9.18
No release notes provided.
Release v0.9.17
No release notes provided.
Release v0.9.16
No release notes provided.
Release v0.9.15
0.9.15 - July 17th, 2018
- Fixed security issue in parsing of Ruby code that could allow for arbitrary execution. Credit to Nelson Elhage [email protected] for discovering this issue.
Release v0.9.14
- Fixed a regression in symbol parsing (#1170).
Release v0.9.13
... (truncated)
Changelog
Sourced from yard's changelog.
0.9.20 - June 27th, 2019
- Fix parsing of stringified Symbols in Ruby source (#1256).
- Fix path traversal vulnerability in
yard server
. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of ayard server
host under certain conditions. Thanks to CuongMX from Viettel Cyber Security for discovering this vulnerability.0.9.19 - April 2nd, 2019
- Fixed bug in browser back button (#1071, #1228)
- Fixed handling of ArgumentError in ExtraFileObject (#1198)
- Fixed double return tag displaying on boolean methods (#1226)
- Removed unused
Module#namespace_name
function (#1229)- Fixed parsing order of README files. YARD will now prefer README over README.md over README.x.md or README-x.md (and the like). READMEs will now also be ordered by filename; the first README is still chosen unless
--readme
is provided.- Updated AsciiDoc markup support to use non-deprecated calls.
0.9.16 - August 11th, 2018
- Documentation fixes (#1175, #1178).
- Fixed stack overflow issue when parsing extremely large lists (#1176).
0.9.15 - July 17th, 2018
- Fixed security issue in parsing of Ruby code that could allow for arbitrary execution. Credit to Nelson Elhage [email protected] for discovering this issue.
0.9.14 - June 2nd, 2018
- Fixed a regression in symbol parsing (#1170).
0.9.13 - May 28th, 2018
... (truncated)
- Added support for grouped constants via
@!group
directive (#1056).
Commits
-
0320b89
Tag release v0.9.20 -
da43056
Update changelog -
01dc2e3
Add .rubocop.yml back for tooling support -
9716717
Fix tests for Ruby <2.6 -
593973c
Disable rubocop -
225ded9
Fix parsing of dyna_symbol nodes -
6d8b9b9
Remove unnecessary debug line -
12f56cf
Tag release v0.9.19 -
6205335
Update dockerfile.samus -
1303dbc
Use credentials in git push - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot ignore this [patch|minor|major] version
will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.