carrierwave-upyun
carrierwave-upyun copied to clipboard
Bump carrierwave from 2.2.2 to 3.0.5
Bumps carrierwave from 2.2.2 to 3.0.5.
Release notes
Sourced from carrierwave's releases.
3.0.4
Fixed
- Fix model's dirty state remaining after update (
@rajyan
#2707, #2702)- Fix #dup modifying the original object (
@rajyan
#2690, #2706, #2689, #2700)- Fix #dup not respecting the :mount_on option, causing MissingAttributeError (
@marsz
#2691)3.0.3
Fixed
- Fix #dup modifying the original object (
@mshibuya
37f36f7, #2687)- Fix wrongly removing files on transaction rollback (
@mshibuya
,@rajyan
eb03fe1, #2686, #2685)3.0.2
Fixed
- Fix deduplicated filename not being persisted (
@mshibuya
#2679, #2678, #2677)3.0.1
Fixed
- Fix not respecting the parent's #enable_processing value after reading its own (
@mshibuya
2df0f53, #2676)- Fix NoMethodError when a record is rolled back (
@y-yagi
#2674, #2675)- Fix filename suffix being removed due to unnecessary deduplication (
@mshibuya
d68a111, #2672)- Fix #dup causing unintended name deduplication of copied files (
@mshibuya
b732acd, #2670)- Fix initialization failing when active_support/core_ext is not loaded yet (
@mshibuya
875d972)3.0.0
Added
- Support adding suffix to filename on store when path collides with the existing ones (
@mshibuya
07a5632, #1855)- Add image dimension validation (
@TsubasaYoshida
#2592, 3b1f8b4)- Provide validation error details via ActiveModel::Errors#details (
@mshibuya
9013999, #2150)- Support clearing #remote_urls by assigning nil (
@mshibuya
8307f93, #2067)- Support configuration of download retry wait time (
@tricknotes
#2646)- Support for ActiveRecord::Base#dup (
@mshibuya
,@BrianHawley
19b33b8, #2645, #1962)- Add CarrierWave::Storage::Fog::File#to_file for interface consistency with SanitizedFile (
@mshibuya
68ce83a, #1960)- Allow SanitizedFile to accept read with an optional length and output_buffer arguments (
@mshibuya
9096459, #1959)- Add basename and fix extension value for fog file (
@leductienttkt
#2587)- Allow uploaders to accept unless conditions (
@Vpatel1093
#2588)- Add retry option to download from remote url (
@tashirosota
#2577)Changed
- Stop relying on ActiveModel::Dirty change tracking for removal of unnecessary files (
@mshibuya
aac25c1)- Create versions lazily to reflect subclass configurations properly (
@mshibuya
1531a67, #1957, #2619)- [BREAKING CHANGE] Use the resulting file extension on changing format by :convert (
@mshibuya
#2659, #2125, #2126, #2254)- Prioritize Magic-detected content type for spoof-tolerance (
@mshibuya
a2ca59c, #2570)- Handle assignments in an ActiveModel::Dirty-friendly way (
@mshibuya
#2658, #2404, #2409, #2468)- Give a stable name to classes created by the mount_uploader block (
@mshibuya
f5b09b8, #2407, #2471)- Give a stable name to version classes (
@mshibuya
a9de756, #2407, #2471)- Completely migrate to allowlist/denylist terminology (
@mshibuya
7a40ef7, #2536)- Remove implementation-dependent information from an error message (
@akihikodaki
#2499)- Replace mini_mime with marcel (
@pjmartorell
#2552)- [BREAKING CHANGE] Change to store files on after_save hook instead of after_commit, with performing cleanup when transaction is rolled back (
@fsateler
#2546)
... (truncated)
Changelog
Sourced from carrierwave's changelog.
3.0.5 - 2023-11-29
Fixed
Security
- Fix Content-Type allowlist bypass vulnerability, possibly leading to XSS (
@mshibuya
, 863d425, GHSA-gxhx-g4fq-49hj)3.0.4 - 2023-10-08
Fixed
- Fix model's dirty state remaining after update (
@rajyan
#2707, #2702)- Fix #dup modifying the original object (
@rajyan
#2690, #2706, #2689, #2700)- Fix #dup not respecting the :mount_on option, causing MissingAttributeError (
@marsz
#2691)3.0.3 - 2023-08-21
Fixed
- Fix #dup modifying the original object (
@mshibuya
37f36f7, #2687)- Fix wrongly removing files on transaction rollback (
@mshibuya
,@rajyan
eb03fe1, #2686, #2685)3.0.2 - 2023-08-01
Fixed
- Fix deduplicated filename not being persisted (
@mshibuya
#2679, #2678, #2677)3.0.1 - 2023-07-22
Fixed
- Fix not respecting the parent's #enable_processing value after reading its own (
@mshibuya
2df0f53, #2676)- Fix NoMethodError when a record is rolled back (
@y-yagi
#2674, #2675)- Fix filename suffix being removed due to unnecessary deduplication (
@mshibuya
d68a111, #2672)- Fix #dup causing unintended name deduplication of copied files (
@mshibuya
b732acd, #2670)- Fix initialization failing when active_support/core_ext is not loaded yet (
@mshibuya
875d972)3.0.0 - 2023-07-02
No changes.
3.0.0.rc - 2023-06-11
Added
- Support adding suffix to filename on store when path collides with the existing ones (
@mshibuya
07a5632, #1855)- Add image dimension validation (
@TsubasaYoshida
#2592, 3b1f8b4)- Provide validation error details via ActiveModel::Errors#details (
@mshibuya
9013999, #2150)- Support clearing #remote_urls by assigning nil (
@mshibuya
8307f93, #2067)- Support configuration of download retry wait time (
@tricknotes
#2646)- Support for ActiveRecord::Base#dup (
@mshibuya
,@BrianHawley
19b33b8, #2645, #1962)- Add CarrierWave::Storage::Fog::File#to_file for interface consistency with SanitizedFile (
@mshibuya
68ce83a, #1960)- Allow SanitizedFile to accept read with an optional length and output_buffer arguments (
@mshibuya
9096459, #1959)
... (truncated)
Commits
5316b35
Version 3.0.5863d425
Fix Content-Type allowlist bypass vulnerabilitya5c0d3c
Fix ruby-head builda4ccfe7
Merge pull request #2711 from rajyan/original-filename-cleanup5c8dc98
deleteif original_filename
as explained in https://github.com/carrierwaveu...0c50a8b
Version 3.0.4969e3aa
Test against Rails 7.139f4da0
Merge pull request #2707 from rajyan/fix-issue-2702c7262b9
add a failing test case for https://github.com/carrierwaveuploader/carrierwav...cfaf173
allow remove_image to be cancelled- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.