Bump actionpack and rails in /examples/simple_rails_api
Bumps actionpack and rails. These dependencies needed to be updated together.
Updates actionpack from 6.0.3.4 to 6.1.4.1
Release notes
Sourced from actionpack's releases.
6.1.4
Active Support
MemCacheStore: convert any underlying value (including
false) to anEntry.See #42559.
Alex Ghiculescu
Fix bug in
number_with_precisionwhen using largeBigDecimalvalues.Fixes #42302.
Federico Aldunate, Zachary Scott
Check byte size instead of length on
secure_compare.Tietew
Fix
Time.atto not lose:inoption.Ryuta Kamizono
Require a path for
config.cache_store = :file_store.Alex Ghiculescu
Avoid having to store complex object in the default translation file.
Rafael Mendonça França
Active Model
Fix
to_jsonforActiveModel::Dirtyobject.Exclude +mutations_from_database+ attribute from json as it lead to recursion.
Anil Maurya
Active Record
Do not try to rollback transactions that failed due to a
ActiveRecord::TransactionRollbackError.Jamie McCarthy
... (truncated)
Changelog
Sourced from actionpack's changelog.
Rails 6.1.4.1 (August 19, 2021)
[CVE-2021-22942] Fix possible open redirect in Host Authorization middleware.
Specially crafted "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
Rails 6.1.4 (June 24, 2021)
Ignore file fixtures on
db:fixtures:loadKevin Sjöberg
Fix ActionController::Live controller test deadlocks by removing the body buffer size limit for tests.
Dylan Thacker-Smith
Correctly place optional path parameter booleans.
Previously, if you specify a url parameter that is part of the path as false it would include that part of the path as parameter for example:
get "(/optional/:optional_id)/things" => "foo#foo", as: :things things_path(optional_id: false) # => /things?optional_id=falseAfter this change, true and false will be treated the same when used as optional path parameters. Meaning now:
get '(this/:my_bool)/that' as: :thatthat_path(my_bool: true) # =>
/this/true/thatthat_path(my_bool: false) # =>/this/false/thatAdam Hess
Add support for 'private, no-store' Cache-Control headers.
Previously, 'no-store' was exclusive; no other directives could be specified.
Alex Smith
Rails 6.1.3.2 (May 05, 2021)
- Prevent open redirects by correctly escaping the host allow list CVE-2021-22903
... (truncated)
Commits
90357afPreparing for 6.1.4.1 releasee63dcc1Bump version / update changelog5e9973dRefactor CVE-2021-22881 fix8321702Preparing for 6.1.4 releasee71539cUpdate CHANGELOG8877b88Merge pull request #42153 from kevinsjoberg/ignore-file-fixtures-on-load5b4466dMerge pull request #41609fab5a81Merge pull request #42437 from HParker/digest-find-parent-controller-template3bbf3acMerge pull request #42244 from hahmed/fix-invalid-statement-compile-errord83a318Merge pull request #42283 from HParker/named-routes-identifies-false- Additional commits viewable in compare view
Updates rails from 6.0.3.4 to 6.1.4.1
Release notes
Sourced from rails's releases.
6.1.4
Active Support
MemCacheStore: convert any underlying value (including
false) to anEntry.See #42559.
Alex Ghiculescu
Fix bug in
number_with_precisionwhen using largeBigDecimalvalues.Fixes #42302.
Federico Aldunate, Zachary Scott
Check byte size instead of length on
secure_compare.Tietew
Fix
Time.atto not lose:inoption.Ryuta Kamizono
Require a path for
config.cache_store = :file_store.Alex Ghiculescu
Avoid having to store complex object in the default translation file.
Rafael Mendonça França
Active Model
Fix
to_jsonforActiveModel::Dirtyobject.Exclude +mutations_from_database+ attribute from json as it lead to recursion.
Anil Maurya
Active Record
Do not try to rollback transactions that failed due to a
ActiveRecord::TransactionRollbackError.Jamie McCarthy
... (truncated)
Commits
90357afPreparing for 6.1.4.1 releasee63dcc1Bump version / update changelog5e9973dRefactor CVE-2021-22881 fix8321702Preparing for 6.1.4 releasee71539cUpdate CHANGELOG15a043fMerge pull request #41677 from anilmaurya/fix-415218877b88Merge pull request #42153 from kevinsjoberg/ignore-file-fixtures-on-load9040eb1Merge pull request #42513 from ghiculescu/ci-ujs-tests5b4466dMerge pull request #41609fab5a81Merge pull request #42437 from HParker/digest-find-parent-controller-template- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.