head 1.5; access; symbols pkgsrc-2026Q2:1.4.0.2 pkgsrc-2026Q2-base:1.4 pkgsrc-2026Q1:1.3.0.4 pkgsrc-2026Q1-base:1.3 pkgsrc-2025Q4:1.3.0.2 pkgsrc-2025Q4-base:1.3 pkgsrc-2025Q3:1.2.0.2 pkgsrc-2025Q3-base:1.2 pkgsrc-2025Q2:1.1.0.6 pkgsrc-2025Q2-base:1.1 pkgsrc-2025Q1:1.1.0.4 pkgsrc-2025Q1-base:1.1 pkgsrc-2024Q4:1.1.0.2 pkgsrc-2024Q4-base:1.1; locks; strict; comment @# @; 1.5 date 2026.07.30.15.20.14; author taca; state Exp; branches; next 1.4; commitid dcBLZI1K4WemSGPG; 1.4 date 2026.03.29.14.07.38; author taca; state Exp; branches 1.4.2.1; next 1.3; commitid 7MD3YzIuBQozqSzG; 1.3 date 2025.11.03.08.40.37; author taca; state Exp; branches 1.3.4.1; next 1.2; commitid yRmstaVYyBboj5hG; 1.2 date 2025.08.14.15.22.46; author taca; state Exp; branches; next 1.1; commitid EsnJg8uLp28F8I6G; 1.1 date 2024.12.13.16.53.09; author taca; state Exp; branches; next ; commitid R8rmMWCno382umBF; 1.4.2.1 date 2026.08.05.15.02.21; author maya; state Exp; branches; next ; commitid y80gCkx7EfojAsQG; 1.3.4.1 date 2026.03.31.13.31.41; author maya; state Exp; branches; next ; commitid iqK8mCnuD32ja8AG; desc @@ 1.5 log @www/ruby-rails72: update to 7.2.3.2 Ruby on Rails 7.2.3.2 (2026-07-29) Active Storage * A possible arbitrary file read and remote code execution in Active Storage variant processing (CVE-2026-66066) @ text @$NetBSD: distinfo,v 1.4 2026/03/29 14:07:38 taca Exp $ BLAKE2s (actioncable-7.2.3.2.gem) = 6c5a1100be2c6b0d913d36895544f5532b9f9ec22de42c9233d83b8812c9fcea SHA512 (actioncable-7.2.3.2.gem) = 992316d2ccd2ed6ddfb1bb30535548261c07a77ea28b0686dedbb448880b36e857601f5c7c68eeb0cf0c0d8bb1b1626cc7891b8b8ae23434008bdd1d291cb87d Size (actioncable-7.2.3.2.gem) = 48128 bytes @ 1.4 log @www/ruby-rails72: update to 7.2.3.1 Ruby on Rails 7.2.3.1 (2026-03-23) Active Support * Reject scientific notation in NumberConverter [CVE-2026-33176] Jean Boussier * Fix SafeBuffer#% to preserve unsafe status [CVE-2026-33170] Jean Boussier * Improve performance of NumberToDelimitedConverter [CVE-2026-33169] Jean Boussier Action View * Skip blank attribute names in tag helpers to avoid generating invalid HTML. [CVE-2026-33168] Mike Dalessio Active Storage * Filter user supplied metadata in DirectUploadController [CVE-2026-33173] Jean Boussier * Configurable maxmimum streaming chunk size Makes sure that byte ranges for blobs don't exceed 100mb by default. Content ranges that are too big can result in denial of service. [CVE-2026-33174] Gannon McGibbon * Limit range requests to a single range [CVE-2026-33658] Jean Boussier * Prevent path traversal in DiskService. DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".", ".."), or if the resolved path is outside the storage root directory. #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for example containing null bytes or having an incompatible encoding. Previously, the exception raised may have been ArgumentError or Encoding::CompatibilityError. DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes. [CVE-2026-33195] Mike Dalessio * Prevent glob injection in DiskService#delete_prefixed. Escape glob metacharacters in the resolved path before passing to Dir.glob. Note that this change breaks any existing code that is relying on delete_prefixed to expand glob metacharacters. This change presumes that is unintended behavior (as other storage services do not respect these metacharacters). [CVE-2026-33202] Mike Dalessio Active Model Active Record Action Pack Active Job Action Mailer Action Cable Action Mailbox Action Text Railties * No change except version. @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.3 2025/11/03 08:40:37 taca Exp $ d3 3 a5 3 BLAKE2s (actioncable-7.2.3.1.gem) = 3e8e596d0691e568d04aca0090d8189a01c9ae3f9731fc2dadc7f08a7c4c3fa3 SHA512 (actioncable-7.2.3.1.gem) = 944e227d52fe1e5842b6487f47b562623361272362fa1af844b70a7e99b6a20d8ecdb24231827216d5f2dfb0d67dd24314983b50abad4aa2cae02af3ba005b03 Size (actioncable-7.2.3.1.gem) = 47616 bytes @ 1.4.2.1 log @Pullup ticket #7214 - requested by taca www/ruby-rails72: Security fix Revisions pulled up: - databases/ruby-activerecord72/distinfo 1.5 - devel/ruby-activejob72/distinfo 1.5 - devel/ruby-activemodel72/distinfo 1.5 - devel/ruby-activestorage72/PLIST 1.2 - devel/ruby-activestorage72/distinfo 1.5 - devel/ruby-activesupport72/distinfo 1.5 - devel/ruby-railties72/distinfo 1.5 - lang/ruby/rails.mk 1.191 - mail/ruby-actionmailbox72/distinfo 1.5 - mail/ruby-actionmailer72/distinfo 1.5 - textproc/ruby-actiontext72/distinfo 1.5 - www/ruby-actioncable72/distinfo 1.5 - www/ruby-actionpack72/distinfo 1.5 - www/ruby-actionview72/distinfo 1.5 - www/ruby-rails72/distinfo 1.5 --- Module Name: pkgsrc Committed By: taca Date: Thu Jul 30 15:20:15 UTC 2026 Modified Files: pkgsrc/databases/ruby-activerecord72: distinfo pkgsrc/devel/ruby-activejob72: distinfo pkgsrc/devel/ruby-activemodel72: distinfo pkgsrc/devel/ruby-activestorage72: PLIST distinfo pkgsrc/devel/ruby-activesupport72: distinfo pkgsrc/devel/ruby-railties72: distinfo pkgsrc/lang/ruby: rails.mk pkgsrc/mail/ruby-actionmailbox72: distinfo pkgsrc/mail/ruby-actionmailer72: distinfo pkgsrc/textproc/ruby-actiontext72: distinfo pkgsrc/www/ruby-actioncable72: distinfo pkgsrc/www/ruby-actionpack72: distinfo pkgsrc/www/ruby-actionview72: distinfo pkgsrc/www/ruby-rails72: distinfo Log Message: www/ruby-rails72: update to 7.2.3.2 Ruby on Rails 7.2.3.2 (2026-07-29) Active Storage * A possible arbitrary file read and remote code execution in Active Storage variant processing (CVE-2026-66066) @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (actioncable-7.2.3.2.gem) = 6c5a1100be2c6b0d913d36895544f5532b9f9ec22de42c9233d83b8812c9fcea SHA512 (actioncable-7.2.3.2.gem) = 992316d2ccd2ed6ddfb1bb30535548261c07a77ea28b0686dedbb448880b36e857601f5c7c68eeb0cf0c0d8bb1b1626cc7891b8b8ae23434008bdd1d291cb87d Size (actioncable-7.2.3.2.gem) = 48128 bytes @ 1.3 log @www/ruby-actioncable72: update to 7.2.3 7.2.3 (2025-10-28) * Fixed compatibility with redis gem 5.4.1 Jean Boussier * Fixed a possible race condition in stream_from. OuYangJinTing * Ensure the Postgresql adapter always use a dedicated connection even during system tests. Fix an issue with the Action Cable Postgresql adapter causing deadlock or various weird pg client error during system tests. Jean Boussier @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.2 2025/08/14 15:22:46 taca Exp $ d3 3 a5 3 BLAKE2s (actioncable-7.2.3.gem) = 336d0eb658f3afe32772f3c25e051e8add8c43672bad7ded9f8c3a446b051c33 SHA512 (actioncable-7.2.3.gem) = f2f6ccd9f79e8714556a36d88eb7aa6953a3024c6badaeaf8e30ed38337edf3935ab7db50980a2c887781b0b6f5c74fca3aa0eb1e45f8791a34e53aef95816c9 Size (actioncable-7.2.3.gem) = 47616 bytes @ 1.3.4.1 log @Pullup ticket #7061 - requested by taca databases/ruby-activerecord72: Security fix devel/ruby-activejob72: Security fix devel/ruby-activemodel72: Security fix devel/ruby-activestorage72: Security fix devel/ruby-activesupport72: Security fix devel/ruby-activesupport72: Security fix devel/ruby-railties72: Security fix devel/ruby-railties72: Security fix lang/ruby: Security fix mail/ruby-actionmailbox72: Security fix mail/ruby-actionmailer72: Security fix textproc/ruby-actiontext72: Security fix www/ruby-actioncable72: Security fix www/ruby-actionpack72: Security fix www/ruby-actionpack72: Security fix www/ruby-actionview72: Security fix www/ruby-rails72: Security fix Revisions pulled up: - databases/ruby-activerecord72/distinfo 1.4 - devel/ruby-activejob72/distinfo 1.4 - devel/ruby-activemodel72/distinfo 1.4 - devel/ruby-activestorage72/distinfo 1.4 - devel/ruby-activesupport72/Makefile 1.4 - devel/ruby-activesupport72/distinfo 1.4 - devel/ruby-railties72/Makefile 1.5 - devel/ruby-railties72/distinfo 1.4 - lang/ruby/rails.mk 1.188 - mail/ruby-actionmailbox72/distinfo 1.4 - mail/ruby-actionmailer72/distinfo 1.4 - textproc/ruby-actiontext72/distinfo 1.4 - www/ruby-actioncable72/distinfo 1.4 - www/ruby-actionpack72/Makefile 1.3 - www/ruby-actionpack72/distinfo 1.4 - www/ruby-actionview72/distinfo 1.4 - www/ruby-rails72/distinfo 1.4 --- Module Name: pkgsrc Committed By: taca Date: Sun Mar 29 14:07:39 UTC 2026 Modified Files: pkgsrc/databases/ruby-activerecord72: distinfo pkgsrc/devel/ruby-activejob72: distinfo pkgsrc/devel/ruby-activemodel72: distinfo pkgsrc/devel/ruby-activestorage72: distinfo pkgsrc/devel/ruby-activesupport72: Makefile distinfo pkgsrc/devel/ruby-railties72: Makefile distinfo pkgsrc/mail/ruby-actionmailbox72: distinfo pkgsrc/mail/ruby-actionmailer72: distinfo pkgsrc/textproc/ruby-actiontext72: distinfo pkgsrc/www/ruby-actioncable72: distinfo pkgsrc/www/ruby-actionpack72: Makefile distinfo pkgsrc/www/ruby-actionview72: distinfo pkgsrc/www/ruby-rails72: distinfo Log Message: www/ruby-rails72: update to 7.2.3.1 Ruby on Rails 7.2.3.1 (2026-03-23) Active Support * Reject scientific notation in NumberConverter [CVE-2026-33176] Jean Boussier * Fix SafeBuffer#% to preserve unsafe status [CVE-2026-33170] Jean Boussier * Improve performance of NumberToDelimitedConverter [CVE-2026-33169] Jean Boussier Action View * Skip blank attribute names in tag helpers to avoid generating invalid HTML. [CVE-2026-33168] Mike Dalessio Active Storage * Filter user supplied metadata in DirectUploadController [CVE-2026-33173] Jean Boussier * Configurable maxmimum streaming chunk size Makes sure that byte ranges for blobs don't exceed 100mb by default. Content ranges that are too big can result in denial of service. [CVE-2026-33174] Gannon McGibbon * Limit range requests to a single range [CVE-2026-33658] Jean Boussier * Prevent path traversal in DiskService. DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".", ".."), or if the resolved path is outside the storage root directory. #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for example containing null bytes or having an incompatible encoding. Previously, the exception raised may have been ArgumentError or Encoding::CompatibilityError. DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes. [CVE-2026-33195] Mike Dalessio * Prevent glob injection in DiskService#delete_prefixed. Escape glob metacharacters in the resolved path before passing to Dir.glob. Note that this change breaks any existing code that is relying on delete_prefixed to expand glob metacharacters. This change presumes that is unintended behavior (as other storage services do not respect these metacharacters). [CVE-2026-33202] Mike Dalessio Active Model Active Record Action Pack Active Job Action Mailer Action Cable Action Mailbox Action Text Railties * No change except version. --- Module Name: pkgsrc Committed By: taca Date: Sun Mar 29 14:26:36 UTC 2026 Modified Files: pkgsrc/lang/ruby: rails.mk Log Message: lang/ruby: update to rails to 7.2.3.1 Make sure to update rails72 to 7.2.3.1. @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (actioncable-7.2.3.1.gem) = 3e8e596d0691e568d04aca0090d8189a01c9ae3f9731fc2dadc7f08a7c4c3fa3 SHA512 (actioncable-7.2.3.1.gem) = 944e227d52fe1e5842b6487f47b562623361272362fa1af844b70a7e99b6a20d8ecdb24231827216d5f2dfb0d67dd24314983b50abad4aa2cae02af3ba005b03 Size (actioncable-7.2.3.1.gem) = 47616 bytes @ 1.2 log @www/ruby-rails72: update to 7.2.2.2 Ruby on Rails 7.2.2.2 (2025-08-13) Active Record * Call inspect on ids in RecordNotFound error [CVE-2025-55193] Gannon McGibbon, John Hawthorn Active Storage * Remove dangerous transformations [CVE-2025-24293] Zack Deveau @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.1 2024/12/13 16:53:09 taca Exp $ d3 3 a5 3 BLAKE2s (actioncable-7.2.2.2.gem) = b617fa0587d788a22186f10a1753aa9860068e8552cc91c549feac33c6455702 SHA512 (actioncable-7.2.2.2.gem) = 404280a8a3d695eb2bf7bbc1294b4c60970cf4abdc30d8fcca24e0d4892713db49c2fbde425c554b0996171bd6b4c41c652ec61d8a2e4cd5180c1bb9c336916f Size (actioncable-7.2.2.2.gem) = 47616 bytes @ 1.1 log @www/ruby-actioncable72: add package version 7.2.2.1 Action Cable - Integrated WebSockets for Rails Action Cable seamlessly integrates WebSockets with the rest of your Rails application. It allows for real-time features to be written in Ruby in the same style and form as the rest of your Rails application, while still being performant and scalable. It's a full-stack offering that provides both a client-side JavaScript framework and a server-side Ruby framework. You have access to your full domain model written with Active Record or your ORM of choice. @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (actioncable-7.2.2.1.gem) = 98e21f40ca99d00d078f9d77b56dd19a7ca7a302cb0f89b4f38e56491f368c3a SHA512 (actioncable-7.2.2.1.gem) = 2d12aa7fb6d9ade02df9e8cadde1e587ece2f966800d404e358050d220124b779de2e07b4229a52bf3e82d7e151e8ae877e78082c0bf25ed1618fe640971af27 Size (actioncable-7.2.2.1.gem) = 47616 bytes @