dorton / HerreraSignIn

HerreraSignIn
1 stars 2 forks source link

Bump rack from 1.4.3 to 1.4.7 #7

Open dependabot[bot] opened 4 years ago

dependabot[bot] commented 4 years ago

Bumps rack from 1.4.3 to 1.4.7.

Changelog *Sourced from [rack's changelog](https://github.com/rack/rack/blob/master/CHANGELOG.md).* > # Changelog > > All notable changes to this project will be documented in this file. For info on how to format all future additions to this file please reference [Keep A Changelog](https://keepachangelog.com/en/1.0.0/). > > ## Unreleased > > _Note: There are many unreleased changes in Rack (`master` is around 300 commits ahead of `2-0-stable`), and below is not an exhaustive list. If you would like to help out and document some of the unreleased changes, PRs are welcome._ > > ### Added > > ### Changed > > - Use `Time#httpdate` format for Expires, as proposed by RFC 7231. ([@​nanaya](https://github.com/nanaya)) > - Make `Utils.status_code` raise an error when the status symbol is invalid instead of `500`. > - Rename `Request::SCHEME_WHITELIST` to `Request::ALLOWED_SCHEMES`. > - Make `Multipart::Parser.get_filename` accept files with `+` in their name. > - Add Falcon to the default handler fallbacks. ([@​ioquatix](https://github.com/ioquatix)) > - Update codebase to avoid string mutations in preparation for `frozen_string_literals`. ([@​pat](https://github.com/pat)) > - Change `MockRequest#env_for` to rely on the input optionally responding to `#size` instead of `#length`. ([@​janko](https://github.com/janko)) > - Rename `Rack::File` -> `Rack::Files` and add deprecation notice. ([@​postmodern](https://github.com/postmodern)). > > ### Removed > > ### Documentation > > - Update broken example in `Session::Abstract::ID` documentation. ([tonytonyjan](https://github.com/tonytonyjan)) > - Add Padrino to the list of frameworks implmenting Rack. ([@​wikimatze](https://github.com/wikimatze)) > - Remove Mongrel from the suggested server options in the help output. ([@​tricknotes](https://github.com/tricknotes)) > - Replace `HISTORY.md` and `NEWS.md` with `CHANGELOG.md`. ([@​twitnithegirl](https://github.com/twitnithegirl)) > - Backfill `CHANGELOG.md` from 2.0.1 to 2.0.7 releases. ([@​drenmi](https://github.com/Drenmi)) > > ## [2.0.8] - 2019-12-08 > > - [[CVE-2019-16782](https://nvd.nist.gov/vuln/detail/CVE-2019-16782)] Prevent timing attacks targeted at session ID lookup. ([@​tenderlove](https://github.com/tenderlove), [@​rafaelfranca](https://github.com/rafaelfranca)) > > ## [1.6.12] - 2019-12-08 > > - [[CVE-2019-16782](https://nvd.nist.gov/vuln/detail/CVE-2019-16782)] Prevent timing attacks targeted at session ID lookup. ([@​tenderlove](https://github.com/tenderlove), [@​rafaelfranca](https://github.com/rafaelfranca)) > > ## [2.0.7] - 2019-04-02 > > ### Fixed > > - Remove calls to `#eof?` on Rack input in `Multipart::Parser`, as this breaks the specification. ([@​matthewd](https://github.com/matthewd)) > - Preserve forwarded IP addresses for trusted proxy chains. ([@​SamSaffron](https://github.com/SamSaffron)) > > ## [2.0.6] - 2018-11-05 > > ### Fixed > > ... (truncated)
Commits - [`f5c0968`](https://github.com/rack/rack/commit/f5c09684fb93dbe76d7b9d0a0411d32ba5d66d04) bumping version - [`bf5bd20`](https://github.com/rack/rack/commit/bf5bd20c38a7b748da44ce7dbb04f3eb7b4e84ba) Merge pull request [#814](https://github-redirect.dependabot.com/rack/rack/issues/814) from johnnaegle/only_increment_open_file_count_for_fi... - [`e4f4df5`](https://github.com/rack/rack/commit/e4f4df517b73ee4e7d365891f4ac2fb6a09a026c) Explicitly fail when hitting the multipart limit - [`1ae52c1`](https://github.com/rack/rack/commit/1ae52c1b5996c03c35090d611c13b1678eb635a2) bumping the release - [`88b067e`](https://github.com/rack/rack/commit/88b067e1bb965bb85fa0fcf343b670d07d388f87) raise an exception if the parameters are too deep - [`688516a`](https://github.com/rack/rack/commit/688516a818e16b1e954cb5c7b55db29e7675b771) Prevent signals from being sent to pid 0 - [`9939d40`](https://github.com/rack/rack/commit/9939d40a5e23dcb058751d1029b794aa2f551900) Bump version number - [`56374f2`](https://github.com/rack/rack/commit/56374f29e293e1db4ad6462e1d03fc01d01a715c) Update README for todays releases - [`5c9b0de`](https://github.com/rack/rack/commit/5c9b0de3d30971a36e953e6fed24e648daf3a68c) Prevent symlink path traversals - [`6c39dfc`](https://github.com/rack/rack/commit/6c39dfc8e8d8d631730449516cddb9b23a24337c) Use secure_compare for hmac comparison - Additional commits viewable in [compare view](https://github.com/rack/rack/compare/1.4.3...1.4.7)


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dorton/HerreraSignIn/network/alerts).