aspector
aspector copied to clipboard
Bump yard from 0.8.7.6 to 0.9.20
Bumps yard from 0.8.7.6 to 0.9.20.
Release notes
Sourced from yard's releases.
Release v0.9.20
- Fix parsing of stringified Symbols in Ruby source (#1256).
- Fix path traversal vulnerability in
yard server. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of ayard serverhost under certain conditions. Thanks to CuongMX from Viettel Cyber Security for discovering this vulnerability.Release v0.9.19
- Fixed bug in browser back button (#1071, #1228)
- Fixed handling of ArgumentError in ExtraFileObject (#1198)
- Fixed double return tag displaying on boolean methods (#1226)
- Removed unused
Module#namespace_namefunction (#1229)- Fixed parsing order of README files. YARD will now prefer README over README.md over README.x.md or README-x.md (and the like). READMEs will now also be ordered by filename; the first README is still chosen unless
--readmeis provided.- Updated AsciiDoc markup support to use non-deprecated calls.
v0.9.18
No release notes provided.
Release v0.9.17
No release notes provided.
Release v0.9.16
No release notes provided.
Release v0.9.15
0.9.15 - July 17th, 2018
- Fixed security issue in parsing of Ruby code that could allow for arbitrary execution. Credit to Nelson Elhage [email protected] for discovering this issue.
Release v0.9.14
- Fixed a regression in symbol parsing (#1170).
Release v0.9.13
... (truncated)
Changelog
Sourced from yard's changelog.
0.9.20 - June 27th, 2019
- Fix parsing of stringified Symbols in Ruby source (#1256).
- Fix path traversal vulnerability in
yard server. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of ayard serverhost under certain conditions. Thanks to CuongMX from Viettel Cyber Security for discovering this vulnerability.0.9.19 - April 2nd, 2019
- Fixed bug in browser back button (#1071, #1228)
- Fixed handling of ArgumentError in ExtraFileObject (#1198)
- Fixed double return tag displaying on boolean methods (#1226)
- Removed unused
Module#namespace_namefunction (#1229)- Fixed parsing order of README files. YARD will now prefer README over README.md over README.x.md or README-x.md (and the like). READMEs will now also be ordered by filename; the first README is still chosen unless
--readmeis provided.- Updated AsciiDoc markup support to use non-deprecated calls.
0.9.16 - August 11th, 2018
- Documentation fixes (#1175, #1178).
- Fixed stack overflow issue when parsing extremely large lists (#1176).
0.9.15 - July 17th, 2018
- Fixed security issue in parsing of Ruby code that could allow for arbitrary execution. Credit to Nelson Elhage [email protected] for discovering this issue.
0.9.14 - June 2nd, 2018
- Fixed a regression in symbol parsing (#1170).
0.9.13 - May 28th, 2018
... (truncated)
- Added support for grouped constants via
@!groupdirective (#1056).
Commits
0320b89Tag release v0.9.20da43056Update changelog01dc2e3Add .rubocop.yml back for tooling support9716717Fix tests for Ruby <2.6593973cDisable rubocop225ded9Fix parsing of dyna_symbol nodes6d8b9b9Remove unnecessary debug line12f56cfTag release v0.9.196205335Update dockerfile.samus1303dbcUse credentials in git push- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot ignore this [patch|minor|major] versionwill close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.