Though this method was likely never meant to take user input, it was
attempting sanitization. That sanitization could be bypassed with
carefully crafted input.
This commit makes the sanitization more robust by replacing any
occurrances of "/" or "/" with "/ " or " /". It also performs a
first pass to remove one surrounding comment to avoid compatibility
issues for users relying on the existing removal.
This also clarifies in the documentation of annotate that it should not
be provided user input.
[CVE-2023-22794]
Added integer width check to PostgreSQL::Quoting
Given a value outside the range for a 64bit signed integer type
PostgreSQL will treat the column type as numeric. Comparing
integer values against numeric values can result in a slow
sequential scan.
This behavior is configurable via
ActiveRecord::Base.raise_int_wider_than_64bit which defaults to true.
Though this method was likely never meant to take user input, it was
attempting sanitization. That sanitization could be bypassed with
carefully crafted input.
This commit makes the sanitization more robust by replacing any
occurrances of "/" or "/" with "/ " or " /". It also performs a
first pass to remove one surrounding comment to avoid compatibility
issues for users relying on the existing removal.
This also clarifies in the documentation of annotate that it should not
be provided user input.
[CVE-2023-22794]
Added integer width check to PostgreSQL::Quoting
Given a value outside the range for a 64bit signed integer type
PostgreSQL will treat the column type as numeric. Comparing
integer values against numeric values can result in a slow
sequential scan.
This behavior is configurable via
ActiveRecord::Base.raise_int_wider_than_64bit which defaults to true.
[CVE-2022-44566]
Rails 7.0.4 (September 09, 2022)
Symbol is allowed by default for YAML columns
Étienne Barrié
Fix ActiveRecord::Store to serialize as a regular Hash
Previously it would serialize as an ActiveSupport::HashWithIndifferentAccess
which is wasteful and cause problem with YAML safe_load.
Jean Boussier
Add timestamptz as a time zone aware type for PostgreSQL
This is required for correctly parsing timestamp with time zone values in your database.
If you don't want this, you can opt out by adding this initializer:
Though this method was likely never meant to take user input, it was
attempting sanitization. That sanitization could be bypassed with
carefully crafted input.
This commit makes the sanitization more robust by replacing any
occurrances of "/" or "/" with "/ " or " /". It also performs a
first pass to remove one surrounding comment to avoid compatibility
issues for users relying on the existing removal.
This also clarifies in the documentation of annotate that it should not
be provided user input.
[CVE-2023-22794]
Added integer width check to PostgreSQL::Quoting
Given a value outside the range for a 64bit signed integer type
PostgreSQL will treat the column type as numeric. Comparing
integer values against numeric values can result in a slow
sequential scan.
This behavior is configurable via
ActiveRecord::Base.raise_int_wider_than_64bit which defaults to true.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/JessicaML/ScienceMotions-rails/network/alerts).
Bumps activerecord, rails, rspec-rails, webpacker, coffee-rails and sass-rails. These dependencies needed to be updated together. Updates
activerecord
from 5.2.4.1 to 7.0.4.1Release notes
Sourced from activerecord's releases.
... (truncated)
Changelog
Sourced from activerecord's changelog.
... (truncated)
Commits
23e0345
Version 7.0.4.1d7aba06
Make sanitize_as_sql_comment more strict82bcdc0
Added integer width check to PostgreSQL::Quoting8015c2c
Version 7.0.44d9b4b4
Merge pull request #45872 from the-spectator/correct_hwia_encodingc5a407d
Linkify code references [ci-skip]e874cf5
Fix typos [ci-skip]fb09b1b
Don't handle this change for legacy_connection_handling0667ba4
Merge pull request #45773 from eileencodes/only-setup-shared-pools-if-we-have...d60d058
Merge pull request #45744 from fatkodima/mysql-change-column-collationUpdates
rails
from 5.2.4.1 to 7.0.4.1Release notes
Sourced from rails's releases.
... (truncated)
Commits
23e0345
Version 7.0.4.1d7aba06
Make sanitize_as_sql_comment more strict8d82687
Avoid regex backtracking on If-None-Match header2164d4f
Avoid regex backtracking in Inflector.underscorecd46b0e
Use string#split instead of regex for domain partse50e26d
Fix sec issue with _url_host_allowed?82bcdc0
Added integer width check to PostgreSQL::Quoting8015c2c
Version 7.0.4f3c345e
Merge pull request #45964 from jhawthorn/server_timing_safetyff27758
Revert "Merge pull request #44695 from Edouard-chin/ec-tagger-logger-broadcast"Updates
rspec-rails
from 3.9.0 to 6.0.1Release notes
Sourced from rspec-rails's releases.
Changelog
Sourced from rspec-rails's changelog.
... (truncated)
Commits
ce70c2f
v6.0.18f867f4
Changelog for 6.0.1ac38623
Changelog for #2625bc5a3c0
Merge pull request #2625 from rspec/replacement-tagged-logger-support73c0989
Merge pull request #2626 from rspec/fix-build0646044
v6.0.07cd6f93
s/upload_backups_spec.rb/upload_backups_job_spec.rb/g8016684
Merge pull request #2587 from rspec/shanecav84/include-tagged-logging0b4d164
Fixed typo396c68f
This updates Rubocop and uses the .rubocop_rspec_base.yml for consistencyUpdates
webpacker
from 4.2.2 to 5.4.3Changelog
Sourced from webpacker's changelog.
... (truncated)
Commits
e0c998e
Bump for v5.4.3e5ebf86
Bump for v5.4.35fa5a4e
Specify webpack-dev-server to be v3 (#3121)c43f55f
Bump for 5.4.267fa6ed
Match loose setting to quiet warning0a810f0
Bump for 5.4.1a3770ab
Upgrade 5.x minors dependencies (#3120)0bae978
Update yarn.lock file (#3114)b58107f
bump optimize-css-assets-webpack-plugin to 5.0.8 (#3095)bf525f3
[5.x] CI fixes (#3106)Updates
coffee-rails
from 4.2.2 to 5.0.0Changelog
Sourced from coffee-rails's changelog.
Commits
32a2939
Prepare to 5.0.06507f0a
Set the javascripts generator option as true in the railtie5f0e005
Point to rails repository74214e8
Merge pull request #114 from larouxn/rails_6_supporteff9c00
Revert folder structure changes, remove --javascripts flage7ce694
Fix for exclusively Rails 669e6782
TESTING, use my fork of Railsfc8c48c
Conditionally use Rails 6 folder stucture5df5816
Merge pull request #111 from larouxn/stop_testing_below_ruby_2.29bead93
Merge pull request #112 from larouxn/update_travis_jruby_versionUpdates
sass-rails
from 5.1.0 to 6.0.0Release notes
Sourced from sass-rails's releases.
Commits
a77240c
Prepare to 6.0.08dbe4dc
Bump version to 6.0.0.beta3830a8ec
Bump minimum version of sassc-railsff54c20
Fix open-ended dependencyebe9ef7
Bump version to v6.0.0.beta2409d871
Merge pull request #424 from rails/sassc-railsd809900
Recomend to use SassC::Rails::Importer to users requiring sass/rails/importer706526d
Make sass-rails an wrapper for sassc-rails to allow a smooth upgrade pathac38f1e
Merge pull request #423 from gregmolnar/masterd61b999
remove gemnasium badge from readmeDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/JessicaML/ScienceMotions-rails/network/alerts).