A web application that allows citizens to "adopt" a storm drain in San Francisco. In use, and in development at other brigades. Looking for a maintainer or someone interested in developing further in collaboration with others across the country.
Bumps puma from 4.2.1 to 4.3.1. This update includes a security fix.
Vulnerabilities fixed
*Sourced from The GitHub Security Advisory Database.*
> **Moderate severity vulnerability that affects puma**
> ## Keepalive thread overload/DoS
>
> ### Impact
>
> A poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack.
>
> If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough.
>
> ### Patches
>
> This vulnerability is patched in Puma 4.3.1 and 3.12.2.
>
> ### Workarounds
>
> Reverse proxies in front of Puma could be configured to always allow less than X keepalive connections to a Puma cluster or process, where X is the number of threads configured in Puma's thread pool.
>
> ### For more information
>
> If you have any questions or comments about this advisory:
>
> ... (truncated)
>
> Affected versions: >= 4.0.0, < 4.3.1
Release notes
*Sourced from [puma's releases](https://github.com/puma/puma/releases).*
> ## v4.3.0 - Mysterious Traveller
> ![0000492109](https://user-images.githubusercontent.com/845662/68427889-ff59cd00-0178-11ea-8329-8493b3de6906.jpg)
>
> [Mysterious Traveller](https://www.youtube.com/watch?v=bZ44_P6iM18)
>
> * Features
> * Strip whitespace at end of HTTP headers ([#2010](https://github-redirect.dependabot.com/puma/puma/issues/2010))
> * Optimize HTTP parser for JRuby ([#2012](https://github-redirect.dependabot.com/puma/puma/issues/2012))
> * Add SSL support for the control app and cli ([#2046](https://github-redirect.dependabot.com/puma/puma/issues/2046), [#2052](https://github-redirect.dependabot.com/puma/puma/issues/2052))
>
> * Bugfixes
> * Fix Errno::EINVAL when SSL is enabled and browser rejects cert ([#1564](https://github-redirect.dependabot.com/puma/puma/issues/1564))
> * Fix pumactl defaulting puma to development if an environment was not specified ([#2035](https://github-redirect.dependabot.com/puma/puma/issues/2035))
> * Fix closing file stream when reading pid from pidfile ([#2048](https://github-redirect.dependabot.com/puma/puma/issues/2048))
> * Fix a typo in configuration option `--extra_runtime_dependencies` ([#2050](https://github-redirect.dependabot.com/puma/puma/issues/2050))
Changelog
*Sourced from [puma's changelog](https://github.com/puma/puma/blob/master/History.md).*
> ## 4.3.1 and 3.12.2 / 2019-12-05
>
> * Security
> * Fix: a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. CVE-2019-16770.
>
> ## 4.3.0 / 2019-11-07
>
> * Features
> * Strip whitespace at end of HTTP headers ([#2010](https://github-redirect.dependabot.com/puma/puma/issues/2010))
> * Optimize HTTP parser for JRuby ([#2012](https://github-redirect.dependabot.com/puma/puma/issues/2012))
> * Add SSL support for the control app and cli ([#2046](https://github-redirect.dependabot.com/puma/puma/issues/2046), [#2052](https://github-redirect.dependabot.com/puma/puma/issues/2052))
>
> * Bugfixes
> * Fix Errno::EINVAL when SSL is enabled and browser rejects cert ([#1564](https://github-redirect.dependabot.com/puma/puma/issues/1564))
> * Fix pumactl defaulting puma to development if an environment was not specified ([#2035](https://github-redirect.dependabot.com/puma/puma/issues/2035))
> * Fix closing file stream when reading pid from pidfile ([#2048](https://github-redirect.dependabot.com/puma/puma/issues/2048))
> * Fix a typo in configuration option `--extra_runtime_dependencies` ([#2050](https://github-redirect.dependabot.com/puma/puma/issues/2050))
Commits
- [`2986bc4`](https://github.com/puma/puma/commit/2986bc4ab5e03072d4c09739649c5c9221b13c8d) 4.3.1
- [`285c3f9`](https://github.com/puma/puma/commit/285c3f963652e8ba6a2835c0f443710abd9c5c32) 4.3.1 and 4.2.1 release notes
- [`98a1f03`](https://github.com/puma/puma/commit/98a1f03e5ebe40cf56b65b0bf60adf97057e0eaf) Merge pull request from GHSA-7xx3-m584-x994
- [`d20242b`](https://github.com/puma/puma/commit/d20242b2ec76cc7e8078986f29f1e083f62ef157) 4.3.0
- [`4852902`](https://github.com/puma/puma/commit/4852902b8992d3d88fea6d485163af86ff847c3d) Merge pull request [#2068](https://github-redirect.dependabot.com/puma/puma/issues/2068) from ahorek/travis_fixes
- [`2d89d7c`](https://github.com/puma/puma/commit/2d89d7ccee9e957058ff313dc78d2607622423c0) travis fixes
- [`3203159`](https://github.com/puma/puma/commit/3203159ac6917cfe7ed2378077e186bc844e34d9) dont set frozen-string-literal for ruby 2.2 [changelog skip] ([#2066](https://github-redirect.dependabot.com/puma/puma/issues/2066))
- [`8e751a8`](https://github.com/puma/puma/commit/8e751a8ce09b7922aa680ed4e30ac73366458243) Add TruffleRuby to (Travis) CI
- [`536c3ed`](https://github.com/puma/puma/commit/536c3ed4a1916aa5c691cd3018a063c9a01cad06) Rubocop failures
- [`554c02c`](https://github.com/puma/puma/commit/554c02cfafcdbdd4d4f9a8c5c8837db6febc7989) Also make request_body_wait_chunked less strict
- Additional commits viewable in [compare view](https://github.com/puma/puma/compare/v4.2.1...v4.3.1)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
- `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com):
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)
Coverage remained the same at 97.931% when pulling 88712683ad66eb5570de13261eebc633faadddaa on dependabot/bundler/puma-4.3.1 into 9de4236503d2c3807f7039199dd0ebe7d2258a06 on master.
Bumps puma from 4.2.1 to 4.3.1. This update includes a security fix.
Vulnerabilities fixed
*Sourced from The GitHub Security Advisory Database.* > **Moderate severity vulnerability that affects puma** > ## Keepalive thread overload/DoS > > ### Impact > > A poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. > > If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough. > > ### Patches > > This vulnerability is patched in Puma 4.3.1 and 3.12.2. > > ### Workarounds > > Reverse proxies in front of Puma could be configured to always allow less than X keepalive connections to a Puma cluster or process, where X is the number of threads configured in Puma's thread pool. > > ### For more information > > If you have any questions or comments about this advisory: > > ... (truncated) > > Affected versions: >= 4.0.0, < 4.3.1Release notes
*Sourced from [puma's releases](https://github.com/puma/puma/releases).* > ## v4.3.0 - Mysterious Traveller > ![0000492109](https://user-images.githubusercontent.com/845662/68427889-ff59cd00-0178-11ea-8329-8493b3de6906.jpg) > > [Mysterious Traveller](https://www.youtube.com/watch?v=bZ44_P6iM18) > > * Features > * Strip whitespace at end of HTTP headers ([#2010](https://github-redirect.dependabot.com/puma/puma/issues/2010)) > * Optimize HTTP parser for JRuby ([#2012](https://github-redirect.dependabot.com/puma/puma/issues/2012)) > * Add SSL support for the control app and cli ([#2046](https://github-redirect.dependabot.com/puma/puma/issues/2046), [#2052](https://github-redirect.dependabot.com/puma/puma/issues/2052)) > > * Bugfixes > * Fix Errno::EINVAL when SSL is enabled and browser rejects cert ([#1564](https://github-redirect.dependabot.com/puma/puma/issues/1564)) > * Fix pumactl defaulting puma to development if an environment was not specified ([#2035](https://github-redirect.dependabot.com/puma/puma/issues/2035)) > * Fix closing file stream when reading pid from pidfile ([#2048](https://github-redirect.dependabot.com/puma/puma/issues/2048)) > * Fix a typo in configuration option `--extra_runtime_dependencies` ([#2050](https://github-redirect.dependabot.com/puma/puma/issues/2050))Changelog
*Sourced from [puma's changelog](https://github.com/puma/puma/blob/master/History.md).* > ## 4.3.1 and 3.12.2 / 2019-12-05 > > * Security > * Fix: a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. CVE-2019-16770. > > ## 4.3.0 / 2019-11-07 > > * Features > * Strip whitespace at end of HTTP headers ([#2010](https://github-redirect.dependabot.com/puma/puma/issues/2010)) > * Optimize HTTP parser for JRuby ([#2012](https://github-redirect.dependabot.com/puma/puma/issues/2012)) > * Add SSL support for the control app and cli ([#2046](https://github-redirect.dependabot.com/puma/puma/issues/2046), [#2052](https://github-redirect.dependabot.com/puma/puma/issues/2052)) > > * Bugfixes > * Fix Errno::EINVAL when SSL is enabled and browser rejects cert ([#1564](https://github-redirect.dependabot.com/puma/puma/issues/1564)) > * Fix pumactl defaulting puma to development if an environment was not specified ([#2035](https://github-redirect.dependabot.com/puma/puma/issues/2035)) > * Fix closing file stream when reading pid from pidfile ([#2048](https://github-redirect.dependabot.com/puma/puma/issues/2048)) > * Fix a typo in configuration option `--extra_runtime_dependencies` ([#2050](https://github-redirect.dependabot.com/puma/puma/issues/2050))Commits
- [`2986bc4`](https://github.com/puma/puma/commit/2986bc4ab5e03072d4c09739649c5c9221b13c8d) 4.3.1 - [`285c3f9`](https://github.com/puma/puma/commit/285c3f963652e8ba6a2835c0f443710abd9c5c32) 4.3.1 and 4.2.1 release notes - [`98a1f03`](https://github.com/puma/puma/commit/98a1f03e5ebe40cf56b65b0bf60adf97057e0eaf) Merge pull request from GHSA-7xx3-m584-x994 - [`d20242b`](https://github.com/puma/puma/commit/d20242b2ec76cc7e8078986f29f1e083f62ef157) 4.3.0 - [`4852902`](https://github.com/puma/puma/commit/4852902b8992d3d88fea6d485163af86ff847c3d) Merge pull request [#2068](https://github-redirect.dependabot.com/puma/puma/issues/2068) from ahorek/travis_fixes - [`2d89d7c`](https://github.com/puma/puma/commit/2d89d7ccee9e957058ff313dc78d2607622423c0) travis fixes - [`3203159`](https://github.com/puma/puma/commit/3203159ac6917cfe7ed2378077e186bc844e34d9) dont set frozen-string-literal for ruby 2.2 [changelog skip] ([#2066](https://github-redirect.dependabot.com/puma/puma/issues/2066)) - [`8e751a8`](https://github.com/puma/puma/commit/8e751a8ce09b7922aa680ed4e30ac73366458243) Add TruffleRuby to (Travis) CI - [`536c3ed`](https://github.com/puma/puma/commit/536c3ed4a1916aa5c691cd3018a063c9a01cad06) Rubocop failures - [`554c02c`](https://github.com/puma/puma/commit/554c02cfafcdbdd4d4f9a8c5c8837db6febc7989) Also make request_body_wait_chunked less strict - Additional commits viewable in [compare view](https://github.com/puma/puma/compare/v4.2.1...v4.3.1)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Pull request limits (per update run and/or open at any time) - Automerge options (never/patch/minor, and dev/runtime dependencies) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired)