head 1.5; access; symbols pkgsrc-2026Q2:1.4.0.2 pkgsrc-2026Q2-base:1.4 pkgsrc-2026Q1:1.3.0.4 pkgsrc-2026Q1-base:1.3 pkgsrc-2025Q4:1.3.0.2 pkgsrc-2025Q4-base:1.3 pkgsrc-2025Q3:1.2.0.2 pkgsrc-2025Q3-base:1.2 pkgsrc-2025Q2:1.1.0.6 pkgsrc-2025Q2-base:1.1 pkgsrc-2025Q1:1.1.0.4 pkgsrc-2025Q1-base:1.1 pkgsrc-2024Q4:1.1.0.2 pkgsrc-2024Q4-base:1.1; locks; strict; comment @# @; 1.5 date 2026.07.30.15.20.14; author taca; state Exp; branches; next 1.4; commitid dcBLZI1K4WemSGPG; 1.4 date 2026.03.29.14.07.37; author taca; state Exp; branches 1.4.2.1; next 1.3; commitid 7MD3YzIuBQozqSzG; 1.3 date 2025.11.03.08.37.23; author taca; state Exp; branches 1.3.4.1; next 1.2; commitid qSyGMI6re0pfi5hG; 1.2 date 2025.08.14.15.22.46; author taca; state Exp; branches; next 1.1; commitid EsnJg8uLp28F8I6G; 1.1 date 2024.12.13.16.40.32; author taca; state Exp; branches; next ; commitid GRRCn9Nnv8EIpmBF; 1.4.2.1 date 2026.08.05.15.02.20; author maya; state Exp; branches; next ; commitid y80gCkx7EfojAsQG; 1.3.4.1 date 2026.03.31.13.31.40; author maya; state Exp; branches; next ; commitid iqK8mCnuD32ja8AG; desc @@ 1.5 log @www/ruby-rails72: update to 7.2.3.2 Ruby on Rails 7.2.3.2 (2026-07-29) Active Storage * A possible arbitrary file read and remote code execution in Active Storage variant processing (CVE-2026-66066) @ text @$NetBSD: distinfo,v 1.4 2026/03/29 14:07:37 taca Exp $ BLAKE2s (activemodel-7.2.3.2.gem) = 606b98f1985a07690eae9bf854c7a6343b54431932fc34f84a194089cd850ae2 SHA512 (activemodel-7.2.3.2.gem) = 6ac778bfcb0256d1aaf0df386bbaa86aba582f6e09c97c32b65c803b24ab36ea87cdda1c565663fe5766a62d85b9577a422f4fa2813fb32365ce42522b568a6c Size (activemodel-7.2.3.2.gem) = 68096 bytes @ 1.4 log @www/ruby-rails72: update to 7.2.3.1 Ruby on Rails 7.2.3.1 (2026-03-23) Active Support * Reject scientific notation in NumberConverter [CVE-2026-33176] Jean Boussier * Fix SafeBuffer#% to preserve unsafe status [CVE-2026-33170] Jean Boussier * Improve performance of NumberToDelimitedConverter [CVE-2026-33169] Jean Boussier Action View * Skip blank attribute names in tag helpers to avoid generating invalid HTML. [CVE-2026-33168] Mike Dalessio Active Storage * Filter user supplied metadata in DirectUploadController [CVE-2026-33173] Jean Boussier * Configurable maxmimum streaming chunk size Makes sure that byte ranges for blobs don't exceed 100mb by default. Content ranges that are too big can result in denial of service. [CVE-2026-33174] Gannon McGibbon * Limit range requests to a single range [CVE-2026-33658] Jean Boussier * Prevent path traversal in DiskService. DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".", ".."), or if the resolved path is outside the storage root directory. #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for example containing null bytes or having an incompatible encoding. Previously, the exception raised may have been ArgumentError or Encoding::CompatibilityError. DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes. [CVE-2026-33195] Mike Dalessio * Prevent glob injection in DiskService#delete_prefixed. Escape glob metacharacters in the resolved path before passing to Dir.glob. Note that this change breaks any existing code that is relying on delete_prefixed to expand glob metacharacters. This change presumes that is unintended behavior (as other storage services do not respect these metacharacters). [CVE-2026-33202] Mike Dalessio Active Model Active Record Action Pack Active Job Action Mailer Action Cable Action Mailbox Action Text Railties * No change except version. @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.3 2025/11/03 08:37:23 taca Exp $ d3 3 a5 3 BLAKE2s (activemodel-7.2.3.1.gem) = 04eba3b86e61ba97cd755705a432d58c702a12c3a7b287d5b4c07681143d0269 SHA512 (activemodel-7.2.3.1.gem) = 0622974b481629b3246f69474fb0ec261beb8555853278225ba35d6cc0c5ef8476d3066f2db848b88fb7d9ad0fb12d8493745c3efcc98039a07577868705f37d Size (activemodel-7.2.3.1.gem) = 68096 bytes @ 1.4.2.1 log @Pullup ticket #7214 - requested by taca www/ruby-rails72: Security fix Revisions pulled up: - databases/ruby-activerecord72/distinfo 1.5 - devel/ruby-activejob72/distinfo 1.5 - devel/ruby-activemodel72/distinfo 1.5 - devel/ruby-activestorage72/PLIST 1.2 - devel/ruby-activestorage72/distinfo 1.5 - devel/ruby-activesupport72/distinfo 1.5 - devel/ruby-railties72/distinfo 1.5 - lang/ruby/rails.mk 1.191 - mail/ruby-actionmailbox72/distinfo 1.5 - mail/ruby-actionmailer72/distinfo 1.5 - textproc/ruby-actiontext72/distinfo 1.5 - www/ruby-actioncable72/distinfo 1.5 - www/ruby-actionpack72/distinfo 1.5 - www/ruby-actionview72/distinfo 1.5 - www/ruby-rails72/distinfo 1.5 --- Module Name: pkgsrc Committed By: taca Date: Thu Jul 30 15:20:15 UTC 2026 Modified Files: pkgsrc/databases/ruby-activerecord72: distinfo pkgsrc/devel/ruby-activejob72: distinfo pkgsrc/devel/ruby-activemodel72: distinfo pkgsrc/devel/ruby-activestorage72: PLIST distinfo pkgsrc/devel/ruby-activesupport72: distinfo pkgsrc/devel/ruby-railties72: distinfo pkgsrc/lang/ruby: rails.mk pkgsrc/mail/ruby-actionmailbox72: distinfo pkgsrc/mail/ruby-actionmailer72: distinfo pkgsrc/textproc/ruby-actiontext72: distinfo pkgsrc/www/ruby-actioncable72: distinfo pkgsrc/www/ruby-actionpack72: distinfo pkgsrc/www/ruby-actionview72: distinfo pkgsrc/www/ruby-rails72: distinfo Log Message: www/ruby-rails72: update to 7.2.3.2 Ruby on Rails 7.2.3.2 (2026-07-29) Active Storage * A possible arbitrary file read and remote code execution in Active Storage variant processing (CVE-2026-66066) @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (activemodel-7.2.3.2.gem) = 606b98f1985a07690eae9bf854c7a6343b54431932fc34f84a194089cd850ae2 SHA512 (activemodel-7.2.3.2.gem) = 6ac778bfcb0256d1aaf0df386bbaa86aba582f6e09c97c32b65c803b24ab36ea87cdda1c565663fe5766a62d85b9577a422f4fa2813fb32365ce42522b568a6c Size (activemodel-7.2.3.2.gem) = 68096 bytes @ 1.3 log @devel/ruby-activemodel72: update to 7.2.3 7.2.3 (2025-10-28) * Fix has_secure_password to perform confirmation validation of the password even when blank. The validation was incorrectly skipped when the password only contained whitespace characters. Fabio Sangiovanni * Handle missing attributes for ActiveModel::Translation#human_attribute_name. zzak * Fix ActiveModel::AttributeAssignment#assign_attributes to accept objects without each. Kouhei Yanagita @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.2 2025/08/14 15:22:46 taca Exp $ d3 3 a5 3 BLAKE2s (activemodel-7.2.3.gem) = 56224516f7b0241cc51b5e1ea608473da0fb96ffc63bb61c295f898e66b49b58 SHA512 (activemodel-7.2.3.gem) = 208008d525e5f876b70d56f04a5096ea281755b9ea993cd7c9087999d919505096d427bb4e16d4f4066d962699cecc39167270d2d32a78d8a4fa45335d98659d Size (activemodel-7.2.3.gem) = 68096 bytes @ 1.3.4.1 log @Pullup ticket #7061 - requested by taca databases/ruby-activerecord72: Security fix devel/ruby-activejob72: Security fix devel/ruby-activemodel72: Security fix devel/ruby-activestorage72: Security fix devel/ruby-activesupport72: Security fix devel/ruby-activesupport72: Security fix devel/ruby-railties72: Security fix devel/ruby-railties72: Security fix lang/ruby: Security fix mail/ruby-actionmailbox72: Security fix mail/ruby-actionmailer72: Security fix textproc/ruby-actiontext72: Security fix www/ruby-actioncable72: Security fix www/ruby-actionpack72: Security fix www/ruby-actionpack72: Security fix www/ruby-actionview72: Security fix www/ruby-rails72: Security fix Revisions pulled up: - databases/ruby-activerecord72/distinfo 1.4 - devel/ruby-activejob72/distinfo 1.4 - devel/ruby-activemodel72/distinfo 1.4 - devel/ruby-activestorage72/distinfo 1.4 - devel/ruby-activesupport72/Makefile 1.4 - devel/ruby-activesupport72/distinfo 1.4 - devel/ruby-railties72/Makefile 1.5 - devel/ruby-railties72/distinfo 1.4 - lang/ruby/rails.mk 1.188 - mail/ruby-actionmailbox72/distinfo 1.4 - mail/ruby-actionmailer72/distinfo 1.4 - textproc/ruby-actiontext72/distinfo 1.4 - www/ruby-actioncable72/distinfo 1.4 - www/ruby-actionpack72/Makefile 1.3 - www/ruby-actionpack72/distinfo 1.4 - www/ruby-actionview72/distinfo 1.4 - www/ruby-rails72/distinfo 1.4 --- Module Name: pkgsrc Committed By: taca Date: Sun Mar 29 14:07:39 UTC 2026 Modified Files: pkgsrc/databases/ruby-activerecord72: distinfo pkgsrc/devel/ruby-activejob72: distinfo pkgsrc/devel/ruby-activemodel72: distinfo pkgsrc/devel/ruby-activestorage72: distinfo pkgsrc/devel/ruby-activesupport72: Makefile distinfo pkgsrc/devel/ruby-railties72: Makefile distinfo pkgsrc/mail/ruby-actionmailbox72: distinfo pkgsrc/mail/ruby-actionmailer72: distinfo pkgsrc/textproc/ruby-actiontext72: distinfo pkgsrc/www/ruby-actioncable72: distinfo pkgsrc/www/ruby-actionpack72: Makefile distinfo pkgsrc/www/ruby-actionview72: distinfo pkgsrc/www/ruby-rails72: distinfo Log Message: www/ruby-rails72: update to 7.2.3.1 Ruby on Rails 7.2.3.1 (2026-03-23) Active Support * Reject scientific notation in NumberConverter [CVE-2026-33176] Jean Boussier * Fix SafeBuffer#% to preserve unsafe status [CVE-2026-33170] Jean Boussier * Improve performance of NumberToDelimitedConverter [CVE-2026-33169] Jean Boussier Action View * Skip blank attribute names in tag helpers to avoid generating invalid HTML. [CVE-2026-33168] Mike Dalessio Active Storage * Filter user supplied metadata in DirectUploadController [CVE-2026-33173] Jean Boussier * Configurable maxmimum streaming chunk size Makes sure that byte ranges for blobs don't exceed 100mb by default. Content ranges that are too big can result in denial of service. [CVE-2026-33174] Gannon McGibbon * Limit range requests to a single range [CVE-2026-33658] Jean Boussier * Prevent path traversal in DiskService. DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".", ".."), or if the resolved path is outside the storage root directory. #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for example containing null bytes or having an incompatible encoding. Previously, the exception raised may have been ArgumentError or Encoding::CompatibilityError. DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes. [CVE-2026-33195] Mike Dalessio * Prevent glob injection in DiskService#delete_prefixed. Escape glob metacharacters in the resolved path before passing to Dir.glob. Note that this change breaks any existing code that is relying on delete_prefixed to expand glob metacharacters. This change presumes that is unintended behavior (as other storage services do not respect these metacharacters). [CVE-2026-33202] Mike Dalessio Active Model Active Record Action Pack Active Job Action Mailer Action Cable Action Mailbox Action Text Railties * No change except version. --- Module Name: pkgsrc Committed By: taca Date: Sun Mar 29 14:26:36 UTC 2026 Modified Files: pkgsrc/lang/ruby: rails.mk Log Message: lang/ruby: update to rails to 7.2.3.1 Make sure to update rails72 to 7.2.3.1. @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (activemodel-7.2.3.1.gem) = 04eba3b86e61ba97cd755705a432d58c702a12c3a7b287d5b4c07681143d0269 SHA512 (activemodel-7.2.3.1.gem) = 0622974b481629b3246f69474fb0ec261beb8555853278225ba35d6cc0c5ef8476d3066f2db848b88fb7d9ad0fb12d8493745c3efcc98039a07577868705f37d Size (activemodel-7.2.3.1.gem) = 68096 bytes @ 1.2 log @www/ruby-rails72: update to 7.2.2.2 Ruby on Rails 7.2.2.2 (2025-08-13) Active Record * Call inspect on ids in RecordNotFound error [CVE-2025-55193] Gannon McGibbon, John Hawthorn Active Storage * Remove dangerous transformations [CVE-2025-24293] Zack Deveau @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.1 2024/12/13 16:40:32 taca Exp $ d3 3 a5 3 BLAKE2s (activemodel-7.2.2.2.gem) = b2e0781ed02cc2b35c03def74f7ce55208a1f1e3091a159777d2dfb831666da1 SHA512 (activemodel-7.2.2.2.gem) = 78fbc2f9c596d2cc4b05e738e7671e7cdb0de0e26c939417c93fa3e4de976e35052485cec948be1bb93f87639dd377ab9ad239327f07c335d65d3a67cecb891a Size (activemodel-7.2.2.2.gem) = 67584 bytes @ 1.1 log @devel/ruby-activemodel72: add package version 7.2.2.1 Active Model -- model interfaces for Rails Active Model provides a known set of interfaces for usage in model classes. They allow for Action Pack helpers to interact with non-Active Record models, for example. Active Model also helps with building custom ORMs for use outside of the Rails framework. @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (activemodel-7.2.2.1.gem) = 61d9aa7028f2bd5054b17d63f758e40cdd1e9de7701e97cf3d629ee4b2395264 SHA512 (activemodel-7.2.2.1.gem) = c3e7af48d9fa5e946b6243c369946b07f277ea91b5d5d155ae9fa6acfa84096605651837e5fe2ee5d1c1c3c577c03085d9e430b8d9996173d58e7f44c74cd3ef Size (activemodel-7.2.2.1.gem) = 67584 bytes @