Some internal housekeeping on reloads could break custom respond_to?
methods in class objects that referenced reloadable constants. See
#44125 for details.
Xavier Noria
Fixed MariaDB default function support.
Defaults would be written wrong in "db/schema.rb" and not work correctly
if using db:schema:load. Further more the function name would be
added as string content when saving new records.
kaspernj
Fix remove_foreign_key with :if_exists option when foreign key actually exists.
fatkodima
Remove --no-comments flag in structure dumps for PostgreSQL
This broke some apps that used custom schema comments. If you don't want
comments in your structure dump, you can use:
Use the model name as a prefix when filtering encrypted attributes from logs.
For example, when encrypting Person#name it will add person.name as a filter
parameter, instead of just name. This prevents unintended filtering of parameters
with a matching name in other models.
Change ActiveRecord::Coders::YAMLColumn default to safe_load
This adds two new configuration options The configuration options are as
follows:
config.active_storage.use_yaml_unsafe_load
When set to true, this configuration option tells Rails to use the old
"unsafe" YAML loading strategy, maintaining the existing behavior but leaving
the possible escalation vulnerability in place. Setting this option to true
is not recommended, but can aid in upgrading.
The "safe YAML" loading method does not allow all classes to be deserialized
by default. This option allows you to specify classes deemed "safe" in your
application. For example, if your application uses Symbol and Time in
serialized data, you can add Symbol and Time to the allowed list as follows:
Some internal housekeeping on reloads could break custom respond_to?
methods in class objects that referenced reloadable constants. See
#44125 for details.
Xavier Noria
Fixed MariaDB default function support.
Defaults would be written wrong in "db/schema.rb" and not work correctly
if using db:schema:load. Further more the function name would be
added as string content when saving new records.
kaspernj
Fix remove_foreign_key with :if_exists option when foreign key actually exists.
fatkodima
Remove --no-comments flag in structure dumps for PostgreSQL
Some internal housekeeping on reloads could break custom respond_to?
methods in class objects that referenced reloadable constants. See
#44125 for details.
Xavier Noria
Fixed MariaDB default function support.
Defaults would be written wrong in "db/schema.rb" and not work correctly
if using db:schema:load. Further more the function name would be
added as string content when saving new records.
kaspernj
Fix remove_foreign_key with :if_exists option when foreign key actually exists.
fatkodima
Remove --no-comments flag in structure dumps for PostgreSQL
This broke some apps that used custom schema comments. If you don't want
comments in your structure dump, you can use:
Use the model name as a prefix when filtering encrypted attributes from logs.
For example, when encrypting Person#name it will add person.name as a filter
parameter, instead of just name. This prevents unintended filtering of parameters
with a matching name in other models.
Prevent generated job specs from duplicating _job in filenames.
(Nick Flückiger, #2496)
Fix ActiveRecord::TestFixture#uses_transaction by using example description
to replace example name rather than example in our monkey patched
run_in_transaction? method. (Stan Lo, #2495)
Prevent keyword arguments being lost when methods are invoked dynamically
in controller specs. (Josh Cheek, #2509, #2514)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/JessicaML/ScienceMotions-rails/network/alerts).
Bumps activerecord, rails, rspec-rails, webpacker, sass-rails and coffee-rails. These dependencies needed to be updated together. Updates
activerecord
from 5.2.4.1 to 7.0.3.1Release notes
Sourced from activerecord's releases.
... (truncated)
Changelog
Sourced from activerecord's changelog.
... (truncated)
Commits
04972d9
Preparing for 7.0.3.1 release0c68c1f
updating version and changelog9529dc8
Change ActiveRecord::Coders::YAMLColumn default to safe_load3872bc0
Preparing for 7.0.3 releasecd7700b
Merge pull request #45016 from adrianna-chang-shopify/ac-fix-strict-loading-p...f99f422
Merge pull request #45018 from lucthev/lt/strict-false3594d29
Merge pull request #44956 from sato11/document-uses_transactionf154d9b
Merge pull request #45012 from fatkodima/fix-sql-comments-regex46f84bc
activerecord: log unnamed bind params976a543
activerecord: add log sql with unnamed bind testUpdates
rails
from 5.2.4.1 to 7.0.3.1Release notes
Sourced from rails's releases.
... (truncated)
Commits
04972d9
Preparing for 7.0.3.1 release0c68c1f
updating version and changelog9529dc8
Change ActiveRecord::Coders::YAMLColumn default to safe_load3872bc0
Preparing for 7.0.3 release74beedc
Remove incorrect tests54bd582
Merge pull request #44947 from jasonkarns/patch-3082e929
Merge pull request #45027 from rails/fix-tag-helper-regressioncd7700b
Merge pull request #45016 from adrianna-chang-shopify/ac-fix-strict-loading-p...f99f422
Merge pull request #45018 from lucthev/lt/strict-falsefd7dc8f
Merge pull request #45013 from JohnAnon9771/fix/doc-active-record-queryingUpdates
rspec-rails
from 3.9.0 to 5.1.2Release notes
Sourced from rspec-rails's releases.
Changelog
Sourced from rspec-rails's changelog.
... (truncated)
Commits
7faa22c
Version 5.1.242eaba8
Changelog for #259719d6165
Merge pull request #2597 from jasonkarns/patch-14e87c78
Changelog for #25911c35c19
Merge pull request #2591 from taketo1113/controller-spec-update056432f
Version 5.1.1f21521a
Changelog for #2578d7e5638
Merge pull request #2578 from rspec/have-enqueued-mail-fix6f029a8
Add regression check for mailer with global job is and fix swapped argument bug29a0f93
Fix Ruby 2.2 buildsUpdates
webpacker
from 4.2.2 to 5.4.3Changelog
Sourced from webpacker's changelog.
... (truncated)
Commits
e0c998e
Bump for v5.4.3e5ebf86
Bump for v5.4.35fa5a4e
Specify webpack-dev-server to be v3 (#3121)c43f55f
Bump for 5.4.267fa6ed
Match loose setting to quiet warning0a810f0
Bump for 5.4.1a3770ab
Upgrade 5.x minors dependencies (#3120)0bae978
Update yarn.lock file (#3114)b58107f
bump optimize-css-assets-webpack-plugin to 5.0.8 (#3095)bf525f3
[5.x] CI fixes (#3106)Updates
sass-rails
from 5.1.0 to 6.0.0Release notes
Sourced from sass-rails's releases.
Commits
a77240c
Prepare to 6.0.08dbe4dc
Bump version to 6.0.0.beta3830a8ec
Bump minimum version of sassc-railsff54c20
Fix open-ended dependencyebe9ef7
Bump version to v6.0.0.beta2409d871
Merge pull request #424 from rails/sassc-railsd809900
Recomend to use SassC::Rails::Importer to users requiring sass/rails/importer706526d
Make sass-rails an wrapper for sassc-rails to allow a smooth upgrade pathac38f1e
Merge pull request #423 from gregmolnar/masterd61b999
remove gemnasium badge from readmeUpdates
coffee-rails
from 4.2.2 to 5.0.0Changelog
Sourced from coffee-rails's changelog.
Commits
32a2939
Prepare to 5.0.06507f0a
Set the javascripts generator option as true in the railtie5f0e005
Point to rails repository74214e8
Merge pull request #114 from larouxn/rails_6_supporteff9c00
Revert folder structure changes, remove --javascripts flage7ce694
Fix for exclusively Rails 669e6782
TESTING, use my fork of Railsfc8c48c
Conditionally use Rails 6 folder stucture5df5816
Merge pull request #111 from larouxn/stop_testing_below_ruby_2.29bead93
Merge pull request #112 from larouxn/update_travis_jruby_versionDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/JessicaML/ScienceMotions-rails/network/alerts).