Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump rails from 5.2.6 to 5.2.7 #4784

Merged
merged 1 commit into from
Mar 16, 2022
Merged

Conversation

javierm
Copy link
Member

@javierm javierm commented Mar 9, 2022

Bumps rails from 5.2.6 to 5.2.7.

This update solves a security issue involving a possible code injection vulnerability in Rails / Active Storage.

Release notes

Sourced from rails's releases.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@javierm javierm added dependencies Pull requests that updates a dependency security Pull requests that address a security vulnerability labels Mar 9, 2022
@javierm javierm self-assigned this Mar 9, 2022
@javierm javierm added this to Reviewing in Consul Democracy via automation Mar 9, 2022
@javierm javierm moved this from Reviewing to Doing in Consul Democracy Mar 16, 2022
@javierm javierm force-pushed the bump_active_storage_to_5.2.6.3 branch 3 times, most recently from f16bbd2 to c909b85 Compare March 16, 2022 19:32
This version solves a security issue in Active Storage; we're including
it even if most probably no CONSUL applications are affected:

https://discuss.rubyonrails.org/t/cve-2022-21831-possible-code-injection-vulnerability-in-rails-active-storage/80199
@javierm javierm force-pushed the bump_active_storage_to_5.2.6.3 branch from c909b85 to 7ce263e Compare March 16, 2022 19:34
@javierm javierm changed the title Bump rails from 5.2.6 to 5.2.6.3 Bump rails from 5.2.6 to 5.2.7 Mar 16, 2022
@javierm javierm moved this from Doing to Reviewing in Consul Democracy Mar 16, 2022
@javierm javierm merged commit 9b76a5a into master Mar 16, 2022
@javierm javierm deleted the bump_active_storage_to_5.2.6.3 branch March 16, 2022 19:52
Consul Democracy automation moved this from Reviewing to Release 1.5.0 Mar 16, 2022
@microweb10 microweb10 mentioned this pull request May 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that updates a dependency security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant