draupnir
draupnir copied to clipboard
Bump rack from 2.2.4 to 3.0.10
Bumps rack from 2.2.4 to 3.0.10.
Release notes
Sourced from rack's releases.
v3.0.9.1
What's Changed
- Fixed ReDoS in Accept header parsing [CVE-2024-26146]
- Fixed ReDoS in Content Type header parsing [CVE-2024-25126]
- Reject Range headers which are too large [CVE-2024-26141]
Full Changelog: https://github.com/rack/rack/compare/v3.0.9...v3.0.9.1
v3.0.9
What's Changed
- Fix content-length calcuation in Rack:Response#write #2150
Full Changelog: https://github.com/rack/rack/compare/v3.0.8...v3.0.9
v3.0.8
What's Changed
- Backport "Fix some unused variable verbose warnings" by
@skipkayhilin rack/rack#2084New Contributors
@skipkayhilmade their first contribution in rack/rack#2084Full Changelog: https://github.com/rack/rack/compare/v3.0.7...v3.0.8
v3.0.7
What's Changed
- Backport "Make query parameters without = have nil values". by
@jeremyevansin rack/rack#2060Full Changelog: https://github.com/rack/rack/compare/v3.0.6.1...v3.0.7
v3.0.6.1
No release notes provided.
v3.0.4.1
Full Changelog: https://github.com/rack/rack/compare/v3.0.4...v3.0.4.1
v3.0.4
Full Changelog: https://github.com/rack/rack/compare/v3.0.3...v3.0.4
v3.0.3
What's Changed
- Release v3.0.3 by
@ioquatixin rack/rack#2000Full Changelog: https://github.com/rack/rack/compare/v3.0.2...v3.0.3
v3.0.2
Full Changelog: https://github.com/rack/rack/compare/v3.0.1...v3.0.2
... (truncated)
Changelog
Sourced from rack's changelog.
[3.0.10] - 2024-03-21
- Backport #2104 to 3-0-stable: Return empty when parsing a multi-part POST with only one end delimiter. (#2164,
@JoeDupuis)[3.0.9] - 2024-01-31
- Fix incorrect content-length header that was emitted when
Rack::Response#writewas used in some situations. (#2150,@mattbrictson)[3.0.8] - 2023-06-14
- Fix some unused variable verbose warnings. (#2084, [
@jeremyevans],@skipkayhil)[3.0.7] - 2023-03-16
- Make query parameters without
=havenilvalues. (#2059, [@jeremyevans])[3.0.6.1] - 2023-03-13
- [CVE-2023-27539] Avoid ReDoS in header parsing
[3.0.6] - 2023-03-13
- Add
QueryParser#missing_valuefor handling missing values + tests. (#2052, [@ioquatix])[3.0.5] - 2023-03-13
- Split form/query parsing into two steps. (#2038,
@matthewd)[3.0.4.2] - 2023-03-02
- [CVE-2023-27530] Introduce multipart_total_part_limit to limit total parts
[3.0.4.1] - 2023-01-17
- [CVE-2022-44571] Fix ReDoS vulnerability in multipart parser
- [CVE-2022-44570] Fix ReDoS in Rack::Utils.get_byte_ranges
- [CVE-2022-44572] Forbid control characters in attributes (also ReDoS)
[3.0.4] - 2023-01-17
Rack::Request#POSTshould consistently raise errors. Cache errors that occur when invokingRack::Request#POSTso they can be raised again later. (#2010, [@ioquatix])- Fix
Rack::Linterror message forHTTP_CONTENT_TYPEandHTTP_CONTENT_LENGTH. (#2007,@byroot)- Extend
Rack::MethodOverrideto handleQueryParser::ParamsTooDeepErrorerror. (#2006,@byroot)[3.0.3] - 2022-12-27
Fixed
Rack::URLMapuses non-deprecated form ofRegexp.new. (#1998,@weizheheng)
... (truncated)
Commits
d3c545eBump patch version.f856dbdBackport #2104 to 3-0-stablea4bc5e0bump version6efb2ceAvoid 2nd degree polynomial regexp in MediaType4849132Return an empty array when ranges are too largea227cd7Fixing ReDoS in header parsing0b3f997Bump patch version.d3d415eUpdate Ruby versions for external tests: drop v2.7 and add v3.2 and v3.3. (#2...c8b977fFix content-length calcuation in Rack:Response#write (#2150)8d1bf99Update CHANGELOG for 3.0.8 (#2086)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)