Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Oct 17, 2019

Bumps rack and rails. These dependencies needed to be updated together.

Updates rack from 1.0.1 to 2.0.7

Changelog

Sourced from rack's changelog.

Changelog

All notable changes to this project will be documented in this file. For info on how to format all future additions to this file please reference Keep A Changelog

[Unreleased]

Added

Changed

  • Rack::Utils.status_code now raises an error when the status symbol is invalid instead of 500.
  • Rack::Request::SCHEME_WHITELIST has been renamed to Rack::Request::ALLOWED_SCHEMES
  • Rack::Multipart::Parser.get_filename now accepts file that contains + in its name, avoiding the replacement of + to space character since filenames with + are valid.

Removed

History/News Archive

Items below this line are from the previously maintained HISTORY.md and NEWS.md files.

[2.0.0]

  • Rack::Session::Abstract::ID is deprecated. Please change to use Rack::Session::Abstract::Persisted

[2.0.0.alpha] 2015-12-04

  • First-party "SameSite" cookies. Browsers omit SameSite cookies from third-party requests, closing the door on many CSRF attacks.
  • Pass same_site: true (or :strict) to enable: response.set_cookie 'foo', value: 'bar', same_site: true or same_site: :lax to use Lax enforcement: response.set_cookie 'foo', value: 'bar', same_site: :lax
  • Based on version 7 of the Same-site Cookies internet draft:
    https://tools.ietf.org/html/draft-west-first-party-cookies-07
  • Thanks to Ben Toews (@​mastahyeti) and Bob Long (@​bobjflong) for updating to drafts 5 and 7.
  • Add Rack::Events middleware for adding event based middleware: middleware that does not care about the response body, but only cares about doing work at particular points in the request / response lifecycle.
  • Add Rack::Request#authority to calculate the authority under which the response is being made (this will be handy for h2 pushes).
  • Add Rack::Response::Helpers#cache_control and cache_control=. Use this for setting cache control headers on your response objects.
  • Add Rack::Response::Helpers#etag and etag=. Use this for setting etag values on the response.
  • Introduce Rack::Response::Helpers#add_header to add a value to a multi-valued response header. Implemented in terms of other Response#*_header methods, so it's available to any response-like class that includes the Helpers module.
  • Add Rack::Request#add_header to match.
  • Rack::Session::Abstract::ID IS DEPRECATED. Please switch to Rack::Session::Abstract::Persisted. Rack::Session::Abstract::Persisted uses a request object rather than the env hash.
  • Pull ENV access inside the request object in to a module. This will help with legacy Request objects that are ENV based but don't want to inherit from Rack::Request
  • Move most methods on the Rack::Request to a module Rack::Request::Helpers and use public API to get values from the request object. This enables users to mix Rack::Request::Helpers in to their own objects so they can implement (get|set|fetch|each)_header as they see fit (for example a proxy object).
  • Files and directories with + in the name are served correctly. Rather than unescaping paths like a form, we unescape with a URI parser using Rack::Utils.unescape_path. Fixes #265
  • Tempfiles are automatically closed in the case that there were too
    many posted.
  • Added methods for manipulating response headers that don't assume
    they're stored as a Hash. Response-like classes may include the
    Rack::Response::Helpers module if they define these methods:
    • Rack::Response#has_header?
    • Rack::Response#get_header
    • Rack::Response#set_header
... (truncated)
Commits
  • 7fb95db Bumping to 2.0.7 for release
  • ea57610 Merge pull request #1343 from larsxschneider/ls/forward-fix
  • 1bf2188 Preserve forwarded IP address for trusted proxy chains
  • cb1fdb6 Merge pull request #1201 from janko-m/make-multipart-parsing-work-for-chunked...
  • 8376dd1 Bumping version for release
  • 313dd6a Whitelist http/https schemes
  • 37c1160 Reduce buffer size to avoid pathological parsing
  • 99fea65 Merge tag '2.0.5' into 2-0-stable
  • 216b7ca Merge pull request #1296 from tomelm/fix-prefers-plaintext
  • decd976 Bump version for release
  • Additional commits viewable in compare view

Updates rails from 2.3.5 to 6.0.0

Release notes

Sourced from rails's releases.

6.0.0.beta1

Active Support

  • Remove deprecated Module#reachable? method.

    Rafael Mendonça França

  • Remove deprecated #acronym_regex method from Inflections.

    Rafael Mendonça França

  • Fix String#safe_constantize throwing a LoadError for incorrectly cased constant references.

    Keenan Brock

  • Preserve key order passed to ActiveSupport::CacheStore#fetch_multi.

    fetch_multi(*names) now returns its results in the same order as the *names requested, rather than returning cache hits followed by cache misses.

    Gannon McGibbon

  • If the same block is included multiple times for a Concern, an exception is no longer raised.

    Mark J. Titorenko, Vlad Bokov

  • Fix bug where #to_options for ActiveSupport::HashWithIndifferentAccess
    would not act as alias for #symbolize_keys.

    Nick Weiland

  • Improve the logic that detects non-autoloaded constants.

    Jan Habermann, Xavier Noria

  • Deprecate ActiveSupport::Multibyte::Unicode#pack_graphemes(array) and ActiveSuppport::Multibyte::Unicode#unpack_graphemes(string)
    in favor of array.flatten.pack("U*") and string.scan(/\X/).map(&:codepoints), respectively.

    Francesco Rodríguez

  • Deprecate ActiveSupport::Multibyte::Chars.consumes? in favor of String#is_utf8?.

    Francesco Rodríguez

  • Fix duration being rounded to a full second.

      time = DateTime.parse("2018-1-1")
      time += 0.51.seconds
    

    Will now correctly add 0.51 second and not 1 full second.

... (truncated)
Commits
  • 66cabed Preparing for 6.0.0 release
  • f63df2b Merge pull request #36949 from 97jaz/thread-local-prepared-statements
  • 97f9609 Highlight database.yml as code block in multiple databases guide [ci skip]
  • dee31b7 Merge pull request #36946 from eugeneius/return_only_media_type_on_content_ty...
  • d9aab35 Add entry about the classic autoload to the upgrading guide
  • 5b327db Merge pull request #36803 from andrewkress/fix-issue-36799
  • 5eaf39b Add note about human_attribute_name symbol/string
  • e3b2a57 Fix attaching many uploaded files one at a time
  • 5a4305f syncs autoloading guides from master [skip ci]
  • ee5ee98 edits the CHANGELOG [skip ci]
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [rack](https://github.com/rack/rack) and [rails](https://github.com/rails/rails). These dependencies needed to be updated together.

Updates `rack` from 1.0.1 to 2.0.7
- [Release notes](https://github.com/rack/rack/releases)
- [Changelog](https://github.com/rack/rack/blob/master/CHANGELOG.md)
- [Commits](rack/rack@1.0.1...2.0.7)

Updates `rails` from 2.3.5 to 6.0.0
- [Release notes](https://github.com/rails/rails/releases)
- [Commits](rails/rails@v2.3.5...v6.0.0)

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Oct 17, 2019
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Dec 19, 2019

Superseded by #6.

@dependabot dependabot bot closed this Dec 19, 2019
@dependabot dependabot bot deleted the dependabot/bundler/rack-and-rails-2.0.7 branch December 19, 2019 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant