Skip to content

Commit 60eeb70

Browse files
author
taca
committed
www/ruby-rails72: update to 7.2.3.1
Ruby on Rails 7.2.3.1 (2026-03-23) Active Support * Reject scientific notation in NumberConverter [CVE-2026-33176] Jean Boussier * Fix SafeBuffer#% to preserve unsafe status [CVE-2026-33170] Jean Boussier * Improve performance of NumberToDelimitedConverter [CVE-2026-33169] Jean Boussier Action View * Skip blank attribute names in tag helpers to avoid generating invalid HTML. [CVE-2026-33168] Mike Dalessio Active Storage * Filter user supplied metadata in DirectUploadController [CVE-2026-33173] Jean Boussier * Configurable maxmimum streaming chunk size Makes sure that byte ranges for blobs don't exceed 100mb by default. Content ranges that are too big can result in denial of service. [CVE-2026-33174] Gannon McGibbon * Limit range requests to a single range [CVE-2026-33658] Jean Boussier * Prevent path traversal in DiskService. DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".", ".."), or if the resolved path is outside the storage root directory. #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for example containing null bytes or having an incompatible encoding. Previously, the exception raised may have been ArgumentError or Encoding::CompatibilityError. DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes. [CVE-2026-33195] Mike Dalessio * Prevent glob injection in DiskService#delete_prefixed. Escape glob metacharacters in the resolved path before passing to Dir.glob. Note that this change breaks any existing code that is relying on delete_prefixed to expand glob metacharacters. This change presumes that is unintended behavior (as other storage services do not respect these metacharacters). [CVE-2026-33202] Mike Dalessio Active Model Active Record Action Pack Active Job Action Mailer Action Cable Action Mailbox Action Text Railties * No change except version.
1 parent 1a4adb1 commit 60eeb70

16 files changed

Lines changed: 55 additions & 58 deletions

File tree

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
1-
$NetBSD: distinfo,v 1.3 2025/11/03 08:38:51 taca Exp $
1+
$NetBSD: distinfo,v 1.4 2026/03/29 14:07:38 taca Exp $
22

3-
BLAKE2s (activerecord-7.2.3.gem) = 5149e5d4bfdcf1d329d46672ecbe4beb638fa14e2bee10ec5a753502a706a622
4-
SHA512 (activerecord-7.2.3.gem) = 25a47018018553a9a502e5007dfe5e7919849bf2a3a87be9efa4c50a7862a4a5398c04e36377eac8133e8f69aabc1f7c895126db13ca60625cd42806d2f3a34d
5-
Size (activerecord-7.2.3.gem) = 549888 bytes
3+
BLAKE2s (activerecord-7.2.3.1.gem) = eae189b25212dd7d4a15efa5a7880d5e628c5ffb9089aad4745e4db8bb4108be
4+
SHA512 (activerecord-7.2.3.1.gem) = c03ae09b1d3bd8aa61fb1b29499c0b0dbc8636eddd3fd7561dce91d0d44e0387c7f4565df262ed727c8b5cd9b00bded55d115233238e632bb1cda97486faf379
5+
Size (activerecord-7.2.3.1.gem) = 549888 bytes

devel/ruby-activejob72/distinfo

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
1-
$NetBSD: distinfo,v 1.3 2025/11/03 08:38:02 taca Exp $
1+
$NetBSD: distinfo,v 1.4 2026/03/29 14:07:38 taca Exp $
22

3-
BLAKE2s (activejob-7.2.3.gem) = 66900629088c853e0a32bc381020f08bc81b8d0daf6599720a13c6cfd80157fa
4-
SHA512 (activejob-7.2.3.gem) = 3c32d94f5878da6f8164b70d5882cc588c95df74f070658ab26d1b80e93c75c6d7047b63d48911200fa139e948cf04cc1f54b7d31aaa2f3fd40d7c2c96e98bfb
5-
Size (activejob-7.2.3.gem) = 36352 bytes
3+
BLAKE2s (activejob-7.2.3.1.gem) = c4e92b1e4039820c5108326ad9283c3ecc0cb47be3251a851f3483760079e0f0
4+
SHA512 (activejob-7.2.3.1.gem) = 676f704b21ac67a32c8cf2603604586807ea909c5a544709421552ff818c397875aa2c32dc5855bd53e87003855bfddcf13cfcd78b237509dca084d3757648fb
5+
Size (activejob-7.2.3.1.gem) = 36352 bytes

devel/ruby-activemodel72/distinfo

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
1-
$NetBSD: distinfo,v 1.3 2025/11/03 08:37:23 taca Exp $
1+
$NetBSD: distinfo,v 1.4 2026/03/29 14:07:37 taca Exp $
22

3-
BLAKE2s (activemodel-7.2.3.gem) = 56224516f7b0241cc51b5e1ea608473da0fb96ffc63bb61c295f898e66b49b58
4-
SHA512 (activemodel-7.2.3.gem) = 208008d525e5f876b70d56f04a5096ea281755b9ea993cd7c9087999d919505096d427bb4e16d4f4066d962699cecc39167270d2d32a78d8a4fa45335d98659d
5-
Size (activemodel-7.2.3.gem) = 68096 bytes
3+
BLAKE2s (activemodel-7.2.3.1.gem) = 04eba3b86e61ba97cd755705a432d58c702a12c3a7b287d5b4c07681143d0269
4+
SHA512 (activemodel-7.2.3.1.gem) = 0622974b481629b3246f69474fb0ec261beb8555853278225ba35d6cc0c5ef8476d3066f2db848b88fb7d9ad0fb12d8493745c3efcc98039a07577868705f37d
5+
Size (activemodel-7.2.3.1.gem) = 68096 bytes
Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
1-
$NetBSD: distinfo,v 1.3 2025/11/03 08:41:48 taca Exp $
1+
$NetBSD: distinfo,v 1.4 2026/03/29 14:07:38 taca Exp $
22

3-
BLAKE2s (activestorage-7.2.3.gem) = b5938ecea15504312eb8b85be86ed02217a2bcc6b761f95ce790ef1869b1bb72
4-
SHA512 (activestorage-7.2.3.gem) = 6ed74401d06893d96c6cb17618f9af0b7e39f2f873304ab11be9c01212061fe8f88f8e693dad03b2f673b42eb887175a5cbe2e2d72a1df08333e7f026dd5bc83
5-
Size (activestorage-7.2.3.gem) = 66560 bytes
3+
BLAKE2s (activestorage-7.2.3.1.gem) = 04254c9cf7e2210971ce453d48041908f588c11abfaf06994764364072a26360
4+
SHA512 (activestorage-7.2.3.1.gem) = b9e411d27ae4f8abdd76f5a58dff8ae551cd6ac82c7156c67bbd8393d6c30bcc96f3ef0431d0d3099c0e563f61d70855528ca0824f53fae4d736c161eb285e65
5+
Size (activestorage-7.2.3.1.gem) = 68608 bytes

devel/ruby-activesupport72/Makefile

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,7 @@
1-
# $NetBSD: Makefile,v 1.3 2025/11/03 08:36:37 taca Exp $
1+
# $NetBSD: Makefile,v 1.4 2026/03/29 14:07:37 taca Exp $
22

33
DISTNAME= activesupport-${RAILS_VERSION}
44
PKGNAME= ${RUBY_PKGPREFIX}-activesupport${RUBY_RAILS}-${RAILS_VERSION}
5-
PKGREVISION= 1
65
CATEGORIES= devel
76

87
MAINTAINER= pkgsrc-users@NetBSD.org
Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
1-
$NetBSD: distinfo,v 1.3 2025/11/03 08:36:37 taca Exp $
1+
$NetBSD: distinfo,v 1.4 2026/03/29 14:07:37 taca Exp $
22

3-
BLAKE2s (activesupport-7.2.3.gem) = c50d4405dd72ca85bbf4a24f1fec76b13fca0e79f2e2ee4ce8891d7befddcae8
4-
SHA512 (activesupport-7.2.3.gem) = ec255933f78c163803f38df1bd22b6389e624875c5bcb8831d655fa4de8dbfd3cb4f1c5d1475fe2fae53345324ec78869672e8c8eadedf1711c18a60396cc183
5-
Size (activesupport-7.2.3.gem) = 251392 bytes
3+
BLAKE2s (activesupport-7.2.3.1.gem) = 6eca3d600c322d942bf8e69165d680e3c6a532e6b46c88549a3ce803113347d9
4+
SHA512 (activesupport-7.2.3.1.gem) = db9295026920beaa920ebe31abaff50ea5176e2b72b525f2392d3f614b1488c4a05620a6cfed62392bc73ca445121cbe6feac31659238d0da8dcec1f8f7a2c39
5+
Size (activesupport-7.2.3.1.gem) = 251904 bytes

devel/ruby-railties72/Makefile

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,7 @@
1-
# $NetBSD: Makefile,v 1.4 2026/02/11 07:28:54 taca Exp $
1+
# $NetBSD: Makefile,v 1.5 2026/03/29 14:07:38 taca Exp $
22

33
DISTNAME= railties-${RAILS_VERSION}
44
PKGNAME= ${RUBY_PKGPREFIX}-railties${RUBY_RAILS}-${RAILS_VERSION}
5-
PKGREVISION= 1
65
CATEGORIES= devel
76

87
MAINTAINER= pkgsrc-users@NetBSD.org

devel/ruby-railties72/distinfo

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
1-
$NetBSD: distinfo,v 1.3 2025/11/03 08:41:08 taca Exp $
1+
$NetBSD: distinfo,v 1.4 2026/03/29 14:07:38 taca Exp $
22

3-
BLAKE2s (railties-7.2.3.gem) = ea7f89b1662b2a34c698cbaa13d2a41351c9cf648288b4596fb04cb2904a0cb1
4-
SHA512 (railties-7.2.3.gem) = 64664d300780fa52bbaefd85ea13efffdb6c08f6f15c28baedee0d4f3ca7c1eededcba0df1c44cf3ef04c5b26c046e0ceacb0fabdeffe796724db4c08686ddaf
5-
Size (railties-7.2.3.gem) = 182784 bytes
3+
BLAKE2s (railties-7.2.3.1.gem) = a6f4ebe70f8c25eb19a0fef335212f36893949d1142b099bb812a0d9a8bd56c8
4+
SHA512 (railties-7.2.3.1.gem) = d6acfb9ced88b8b2eb3fb9b8fcc0608522cbef7cb0f492005f83f396950e2e174a8971bc00eff5d37b9469a3799d029347b71d588cbda8a4eff22fcad4d37af5
5+
Size (railties-7.2.3.1.gem) = 182784 bytes

mail/ruby-actionmailbox72/distinfo

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
1-
$NetBSD: distinfo,v 1.3 2025/11/03 08:43:48 taca Exp $
1+
$NetBSD: distinfo,v 1.4 2026/03/29 14:07:39 taca Exp $
22

3-
BLAKE2s (actionmailbox-7.2.3.gem) = 2681e7c202220db9c717e80c0770b3d6649a2a0adf76c8228ff9f329ec94c410
4-
SHA512 (actionmailbox-7.2.3.gem) = 74723c015de7a01e54de8b0a888b4136a502e28d2d2d8ceb7daf3dea0ff6233fe23dcba0c010c73e145cdd5276008e7d26a3263c2287c6b3726f0c07b78016a0
5-
Size (actionmailbox-7.2.3.gem) = 22528 bytes
3+
BLAKE2s (actionmailbox-7.2.3.1.gem) = d153b5b452cce8bd85c4f27c84ce9fb67da194694483b8871e3b1ef4f61765d9
4+
SHA512 (actionmailbox-7.2.3.1.gem) = 2198e46f509604770cc46e25e99735fc9199b2b51da9a0b04cb2d41b346e667ffa53aaebedc149d9e9e61e7ff183195cdfb5ce685998d7b06b370ec3447b9ab1
5+
Size (actionmailbox-7.2.3.1.gem) = 22528 bytes

mail/ruby-actionmailer72/distinfo

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
1-
$NetBSD: distinfo,v 1.3 2025/11/03 08:43:48 taca Exp $
1+
$NetBSD: distinfo,v 1.4 2026/03/29 14:07:38 taca Exp $
22

3-
BLAKE2s (actionmailer-7.2.3.gem) = 38b933679402e471d5358d4086989a2effc989d5417087a98c8a3ee9f86ad7ad
4-
SHA512 (actionmailer-7.2.3.gem) = be72104a845bc08516c7b26105079fa0e9e0e6ef7e7f5d0bdb125b5a1a41d0bc386bde157323695657c3f1ac9a2394e05ade0a7bc90bce8ff47ce90fa3cac8e9
5-
Size (actionmailer-7.2.3.gem) = 32256 bytes
3+
BLAKE2s (actionmailer-7.2.3.1.gem) = e7cbf26e6cc1021536115472bd1254d4d231d8cadecb2164d5173c567612aaa1
4+
SHA512 (actionmailer-7.2.3.1.gem) = 6104a69cb0f60c135c73ab6d54e10929396044388bb5f2ef49eebec37140d5453693679cb6d761dbb67d86f0758a10b88fbceb6b240ddc570546dfefef4fdc41
5+
Size (actionmailer-7.2.3.1.gem) = 32256 bytes

0 commit comments

Comments
 (0)