segiddins / segiddins.me

http://segiddins.me/
0 stars 0 forks source link

[Security] Bump rack from 1.6.0 to 1.6.11 #15

Closed dependabot-preview[bot] closed 6 years ago

dependabot-preview[bot] commented 6 years ago

Bumps rack from 1.6.0 to 1.6.11. This update includes security fixes.

Vulnerabilities fixed *Sourced from The Ruby Advisory Database.* > **Possible XSS vulnerability in Rack** > There is a possible XSS vulnerability in Rack. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to "http" or "https" and do not escape the return value could be vulnerable to an XSS attack. > > Vulnerable code looks something like this: > > ``` > <%= request.scheme.html_safe %> > ``` > > Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable. > > All users running an affected release should either upgrade or use one of the workarounds immediately. > > Patched versions: \~> 1.6.11; >= 2.0.6 > Unaffected versions: none *Sourced from [The Ruby Advisory Database](https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2015-3225.yml).* > **Potential Denial of Service Vulnerability in Rack** > Carefully crafted requests can cause a `SystemStackError` and potentially > cause a denial of service attack. > > All users running an affected release should upgrade. > > Patched versions: >= 1.6.2; \~> 1.5.4; \~> 1.4.6 > Unaffected versions: none
Changelog *Sourced from [rack's changelog](https://github.com/rack/rack/blob/master/CHANGELOG.md).* > # Changelog > All notable changes to this project will be documented in this file. For info on how to format all future additions to this file please reference [Keep A Changelog](https://keepachangelog.com/en/1.0.0/) > > ## [Unreleased] > ### Added > - CHANGELOG.md using keep a changelog formatting by [**twitnithegirl**](https://github.com/twitnithegirl) > > ### Changed > - `Rack::Utils.status_code` now raises an error when the status symbol is invalid instead of `500`. > > ### Removed > - HISTORY.md by [**twitnithegirl**](https://github.com/twitnithegirl) > - NEWS.md by [**twitnithegirl**](https://github.com/twitnithegirl) > > > # > # > # History/News Archive > Items below this line are from the previously maintained HISTORY.md and NEWS.md files. > # > > ## [2.0.0] > - Rack::Session::Abstract::ID is deprecated. Please change to use Rack::Session::Abstract::Persisted > > ## [2.0.0.alpha] 2015-12-04 > - First-party "SameSite" cookies. Browsers omit SameSite cookies from third-party requests, closing the door on many CSRF attacks. > - Pass `same_site: true` (or `:strict`) to enable: response.set_cookie 'foo', value: 'bar', same_site: true or `same_site: :lax` to use Lax enforcement: response.set_cookie 'foo', value: 'bar', same_site: :lax > - Based on version 7 of the Same-site Cookies internet draft: > https://tools.ietf.org/html/draft-west-first-party-cookies-07 > - Thanks to Ben Toews ([**mastahyeti**](https://github.com/mastahyeti)) and Bob Long ([**bobjflong**](https://github.com/bobjflong)) for updating to drafts 5 and 7. > - Add `Rack::Events` middleware for adding event based middleware: middleware that does not care about the response body, but only cares about doing work at particular points in the request / response lifecycle. > - Add `Rack::Request#authority` to calculate the authority under which the response is being made (this will be handy for h2 pushes). > - Add `Rack::Response::Helpers#cache_control` and `cache_control=`. Use this for setting cache control headers on your response objects. > - Add `Rack::Response::Helpers#etag` and `etag=`. Use this for setting etag values on the response. > - Introduce `Rack::Response::Helpers#add_header` to add a value to a multi-valued response header. Implemented in terms of other `Response#*_header` methods, so it's available to any response-like class that includes the `Helpers` module. > - Add `Rack::Request#add_header` to match. > - `Rack::Session::Abstract::ID` IS DEPRECATED. Please switch to `Rack::Session::Abstract::Persisted`. `Rack::Session::Abstract::Persisted` uses a request object rather than the `env` hash. > - Pull `ENV` access inside the request object in to a module. This will help with legacy Request objects that are ENV based but don't want to inherit from Rack::Request > - Move most methods on the `Rack::Request` to a module `Rack::Request::Helpers` and use public API to get values from the request object. This enables users to mix `Rack::Request::Helpers` in to their own objects so they can implement `(get|set|fetch|each)_header` as they see fit (for example a proxy object). > - Files and directories with + in the name are served correctly. Rather than unescaping paths like a form, we unescape with a URI parser using `Rack::Utils.unescape_path`. Fixes [#265](https://github-redirect.dependabot.com/rack/rack/issues/265) > - Tempfiles are automatically closed in the case that there were too > many posted. > - Added methods for manipulating response headers that don't assume > they're stored as a Hash. Response-like classes may include the > Rack::Response::Helpers module if they define these methods: > - Rack::Response#has_header? > - Rack::Response#get_header > - Rack::Response#set_header > - Rack::Response#delete_header > - Introduce Util.get_byte_ranges that will parse the value of the HTTP_RANGE string passed to it without depending on the `env` hash. `byte_ranges` is deprecated in favor of this method. > ... (truncated)
Commits - [`2bef132`](https://github.com/rack/rack/commit/2bef132505cb2f80c432e3f4526dfef969cd2e25) Bumping version for release - [`97ca63d`](https://github.com/rack/rack/commit/97ca63d87d88b4088fb1995b14103d4fe6a5e594) Whitelist http/https schemes - [`7b5054e`](https://github.com/rack/rack/commit/7b5054eedfdbd8f7dd5f348b0a02678b64fdd9de) Merge pull request [#1296](https://github-redirect.dependabot.com/rack/rack/issues/1296) from tomelm/fix-prefers-plaintext - [`fdcd03a`](https://github.com/rack/rack/commit/fdcd03a3c5a1c51d1f96fc97f9dfa1a9deac0c77) Bump version for release - [`2293c6a`](https://github.com/rack/rack/commit/2293c6a21925a70a2e9e67138edd341c5418ec4b) Merge pull request [#1249](https://github-redirect.dependabot.com/rack/rack/issues/1249) from mclark/handle-invalid-method-parameters - [`b27dd86`](https://github.com/rack/rack/commit/b27dd86738c21110cc5e8befa2fa217f81124ee3) handle failure to upcase invalid strings - [`274d934`](https://github.com/rack/rack/commit/274d934f32cc08a550f9e37bfdced7e228b42196) Stick with a passing version of Rubygems and bundler - [`617aac0`](https://github.com/rack/rack/commit/617aac0fb89f25603afc2b6497fdc3333354aee5) bump version for release - [`dc017e7`](https://github.com/rack/rack/commit/dc017e78612ae96e222cee8619dba0bb1dbc11a9) Merge pull request [#1237](https://github-redirect.dependabot.com/rack/rack/issues/1237) from eileencodes/backport-1137 - [`4d6965a`](https://github.com/rack/rack/commit/4d6965abb840d4543bcaf00e96482afe94442045) Backport pull request [#1137](https://github-redirect.dependabot.com/rack/rack/issues/1137) from unabridged/fix-eof-failure - Additional commits viewable in [compare view](https://github.com/rack/rack/compare/1.6.0...1.6.11)


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Note: This repo was added to Dependabot recently, so you'll receive a maximum of 5 PRs for your first few update runs. Once an update run creates fewer than 5 PRs we'll remove that limit.

You can always request more updates by clicking Bump now in your Dependabot dashboard.

Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Automerge options (never/patch/minor, and dev/runtime dependencies) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired) Finally, you can contact us by mentioning @dependabot.
segiddins commented 6 years ago

@dependabot merge