head 1.5; access; symbols pkgsrc-2026Q2:1.4.0.2 pkgsrc-2026Q2-base:1.4 pkgsrc-2026Q1:1.3.0.4 pkgsrc-2026Q1-base:1.3 pkgsrc-2025Q4:1.3.0.2 pkgsrc-2025Q4-base:1.3 pkgsrc-2025Q3:1.2.0.2 pkgsrc-2025Q3-base:1.2 pkgsrc-2025Q2:1.1.0.6 pkgsrc-2025Q2-base:1.1 pkgsrc-2025Q1:1.1.0.4 pkgsrc-2025Q1-base:1.1 pkgsrc-2024Q4:1.1.0.2 pkgsrc-2024Q4-base:1.1; locks; strict; comment @# @; 1.5 date 2026.07.30.15.20.14; author taca; state Exp; branches; next 1.4; commitid dcBLZI1K4WemSGPG; 1.4 date 2026.03.29.14.07.38; author taca; state Exp; branches 1.4.2.1; next 1.3; commitid 7MD3YzIuBQozqSzG; 1.3 date 2025.11.03.08.41.08; author taca; state Exp; branches 1.3.4.1; next 1.2; commitid Q9kwqcS7tlIzj5hG; 1.2 date 2025.08.14.15.22.46; author taca; state Exp; branches; next 1.1; commitid EsnJg8uLp28F8I6G; 1.1 date 2024.12.13.16.55.10; author taca; state Exp; branches; next ; commitid CMaBsrul1g7JumBF; 1.4.2.1 date 2026.08.05.15.02.20; author maya; state Exp; branches; next ; commitid y80gCkx7EfojAsQG; 1.3.4.1 date 2026.03.31.13.31.41; author maya; state Exp; branches; next ; commitid iqK8mCnuD32ja8AG; desc @@ 1.5 log @www/ruby-rails72: update to 7.2.3.2 Ruby on Rails 7.2.3.2 (2026-07-29) Active Storage * A possible arbitrary file read and remote code execution in Active Storage variant processing (CVE-2026-66066) @ text @$NetBSD: distinfo,v 1.4 2026/03/29 14:07:38 taca Exp $ BLAKE2s (railties-7.2.3.2.gem) = 1b9f4c59d35946c63c85db99c2de947161ec714cfb7c44d4eee7660392acf938 SHA512 (railties-7.2.3.2.gem) = b929208ffd205286e55b45bc9b8cc557a42bfdfa4871cd2c2b8c41a4ba7e1cc15ce074f00aeb12b56f9570dcdd50cedbe280c3373cea921215d455ccb1c83f08 Size (railties-7.2.3.2.gem) = 182784 bytes @ 1.4 log @www/ruby-rails72: update to 7.2.3.1 Ruby on Rails 7.2.3.1 (2026-03-23) Active Support * Reject scientific notation in NumberConverter [CVE-2026-33176] Jean Boussier * Fix SafeBuffer#% to preserve unsafe status [CVE-2026-33170] Jean Boussier * Improve performance of NumberToDelimitedConverter [CVE-2026-33169] Jean Boussier Action View * Skip blank attribute names in tag helpers to avoid generating invalid HTML. [CVE-2026-33168] Mike Dalessio Active Storage * Filter user supplied metadata in DirectUploadController [CVE-2026-33173] Jean Boussier * Configurable maxmimum streaming chunk size Makes sure that byte ranges for blobs don't exceed 100mb by default. Content ranges that are too big can result in denial of service. [CVE-2026-33174] Gannon McGibbon * Limit range requests to a single range [CVE-2026-33658] Jean Boussier * Prevent path traversal in DiskService. DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".", ".."), or if the resolved path is outside the storage root directory. #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for example containing null bytes or having an incompatible encoding. Previously, the exception raised may have been ArgumentError or Encoding::CompatibilityError. DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes. [CVE-2026-33195] Mike Dalessio * Prevent glob injection in DiskService#delete_prefixed. Escape glob metacharacters in the resolved path before passing to Dir.glob. Note that this change breaks any existing code that is relying on delete_prefixed to expand glob metacharacters. This change presumes that is unintended behavior (as other storage services do not respect these metacharacters). [CVE-2026-33202] Mike Dalessio Active Model Active Record Action Pack Active Job Action Mailer Action Cable Action Mailbox Action Text Railties * No change except version. @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.3 2025/11/03 08:41:08 taca Exp $ d3 3 a5 3 BLAKE2s (railties-7.2.3.1.gem) = a6f4ebe70f8c25eb19a0fef335212f36893949d1142b099bb812a0d9a8bd56c8 SHA512 (railties-7.2.3.1.gem) = d6acfb9ced88b8b2eb3fb9b8fcc0608522cbef7cb0f492005f83f396950e2e174a8971bc00eff5d37b9469a3799d029347b71d588cbda8a4eff22fcad4d37af5 Size (railties-7.2.3.1.gem) = 182784 bytes @ 1.4.2.1 log @Pullup ticket #7214 - requested by taca www/ruby-rails72: Security fix Revisions pulled up: - databases/ruby-activerecord72/distinfo 1.5 - devel/ruby-activejob72/distinfo 1.5 - devel/ruby-activemodel72/distinfo 1.5 - devel/ruby-activestorage72/PLIST 1.2 - devel/ruby-activestorage72/distinfo 1.5 - devel/ruby-activesupport72/distinfo 1.5 - devel/ruby-railties72/distinfo 1.5 - lang/ruby/rails.mk 1.191 - mail/ruby-actionmailbox72/distinfo 1.5 - mail/ruby-actionmailer72/distinfo 1.5 - textproc/ruby-actiontext72/distinfo 1.5 - www/ruby-actioncable72/distinfo 1.5 - www/ruby-actionpack72/distinfo 1.5 - www/ruby-actionview72/distinfo 1.5 - www/ruby-rails72/distinfo 1.5 --- Module Name: pkgsrc Committed By: taca Date: Thu Jul 30 15:20:15 UTC 2026 Modified Files: pkgsrc/databases/ruby-activerecord72: distinfo pkgsrc/devel/ruby-activejob72: distinfo pkgsrc/devel/ruby-activemodel72: distinfo pkgsrc/devel/ruby-activestorage72: PLIST distinfo pkgsrc/devel/ruby-activesupport72: distinfo pkgsrc/devel/ruby-railties72: distinfo pkgsrc/lang/ruby: rails.mk pkgsrc/mail/ruby-actionmailbox72: distinfo pkgsrc/mail/ruby-actionmailer72: distinfo pkgsrc/textproc/ruby-actiontext72: distinfo pkgsrc/www/ruby-actioncable72: distinfo pkgsrc/www/ruby-actionpack72: distinfo pkgsrc/www/ruby-actionview72: distinfo pkgsrc/www/ruby-rails72: distinfo Log Message: www/ruby-rails72: update to 7.2.3.2 Ruby on Rails 7.2.3.2 (2026-07-29) Active Storage * A possible arbitrary file read and remote code execution in Active Storage variant processing (CVE-2026-66066) @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (railties-7.2.3.2.gem) = 1b9f4c59d35946c63c85db99c2de947161ec714cfb7c44d4eee7660392acf938 SHA512 (railties-7.2.3.2.gem) = b929208ffd205286e55b45bc9b8cc557a42bfdfa4871cd2c2b8c41a4ba7e1cc15ce074f00aeb12b56f9570dcdd50cedbe280c3373cea921215d455ccb1c83f08 Size (railties-7.2.3.2.gem) = 182784 bytes @ 1.3 log @devel/ruby-railties72: update to 7.2.3 7.2.3 (2025-10-28) * Use secret_key_base from ENV or credentials when present locally. When ENV["SECRET_KEY_BASE"] or Rails.application.credentials.secret_key_base is set for test or development, it is used for the Rails.config.secret_key_base, instead of generating a tmp/local_secret.txt file. Petrik de Heus @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.2 2025/08/14 15:22:46 taca Exp $ d3 3 a5 3 BLAKE2s (railties-7.2.3.gem) = ea7f89b1662b2a34c698cbaa13d2a41351c9cf648288b4596fb04cb2904a0cb1 SHA512 (railties-7.2.3.gem) = 64664d300780fa52bbaefd85ea13efffdb6c08f6f15c28baedee0d4f3ca7c1eededcba0df1c44cf3ef04c5b26c046e0ceacb0fabdeffe796724db4c08686ddaf Size (railties-7.2.3.gem) = 182784 bytes @ 1.3.4.1 log @Pullup ticket #7061 - requested by taca databases/ruby-activerecord72: Security fix devel/ruby-activejob72: Security fix devel/ruby-activemodel72: Security fix devel/ruby-activestorage72: Security fix devel/ruby-activesupport72: Security fix devel/ruby-activesupport72: Security fix devel/ruby-railties72: Security fix devel/ruby-railties72: Security fix lang/ruby: Security fix mail/ruby-actionmailbox72: Security fix mail/ruby-actionmailer72: Security fix textproc/ruby-actiontext72: Security fix www/ruby-actioncable72: Security fix www/ruby-actionpack72: Security fix www/ruby-actionpack72: Security fix www/ruby-actionview72: Security fix www/ruby-rails72: Security fix Revisions pulled up: - databases/ruby-activerecord72/distinfo 1.4 - devel/ruby-activejob72/distinfo 1.4 - devel/ruby-activemodel72/distinfo 1.4 - devel/ruby-activestorage72/distinfo 1.4 - devel/ruby-activesupport72/Makefile 1.4 - devel/ruby-activesupport72/distinfo 1.4 - devel/ruby-railties72/Makefile 1.5 - devel/ruby-railties72/distinfo 1.4 - lang/ruby/rails.mk 1.188 - mail/ruby-actionmailbox72/distinfo 1.4 - mail/ruby-actionmailer72/distinfo 1.4 - textproc/ruby-actiontext72/distinfo 1.4 - www/ruby-actioncable72/distinfo 1.4 - www/ruby-actionpack72/Makefile 1.3 - www/ruby-actionpack72/distinfo 1.4 - www/ruby-actionview72/distinfo 1.4 - www/ruby-rails72/distinfo 1.4 --- Module Name: pkgsrc Committed By: taca Date: Sun Mar 29 14:07:39 UTC 2026 Modified Files: pkgsrc/databases/ruby-activerecord72: distinfo pkgsrc/devel/ruby-activejob72: distinfo pkgsrc/devel/ruby-activemodel72: distinfo pkgsrc/devel/ruby-activestorage72: distinfo pkgsrc/devel/ruby-activesupport72: Makefile distinfo pkgsrc/devel/ruby-railties72: Makefile distinfo pkgsrc/mail/ruby-actionmailbox72: distinfo pkgsrc/mail/ruby-actionmailer72: distinfo pkgsrc/textproc/ruby-actiontext72: distinfo pkgsrc/www/ruby-actioncable72: distinfo pkgsrc/www/ruby-actionpack72: Makefile distinfo pkgsrc/www/ruby-actionview72: distinfo pkgsrc/www/ruby-rails72: distinfo Log Message: www/ruby-rails72: update to 7.2.3.1 Ruby on Rails 7.2.3.1 (2026-03-23) Active Support * Reject scientific notation in NumberConverter [CVE-2026-33176] Jean Boussier * Fix SafeBuffer#% to preserve unsafe status [CVE-2026-33170] Jean Boussier * Improve performance of NumberToDelimitedConverter [CVE-2026-33169] Jean Boussier Action View * Skip blank attribute names in tag helpers to avoid generating invalid HTML. [CVE-2026-33168] Mike Dalessio Active Storage * Filter user supplied metadata in DirectUploadController [CVE-2026-33173] Jean Boussier * Configurable maxmimum streaming chunk size Makes sure that byte ranges for blobs don't exceed 100mb by default. Content ranges that are too big can result in denial of service. [CVE-2026-33174] Gannon McGibbon * Limit range requests to a single range [CVE-2026-33658] Jean Boussier * Prevent path traversal in DiskService. DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".", ".."), or if the resolved path is outside the storage root directory. #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for example containing null bytes or having an incompatible encoding. Previously, the exception raised may have been ArgumentError or Encoding::CompatibilityError. DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes. [CVE-2026-33195] Mike Dalessio * Prevent glob injection in DiskService#delete_prefixed. Escape glob metacharacters in the resolved path before passing to Dir.glob. Note that this change breaks any existing code that is relying on delete_prefixed to expand glob metacharacters. This change presumes that is unintended behavior (as other storage services do not respect these metacharacters). [CVE-2026-33202] Mike Dalessio Active Model Active Record Action Pack Active Job Action Mailer Action Cable Action Mailbox Action Text Railties * No change except version. --- Module Name: pkgsrc Committed By: taca Date: Sun Mar 29 14:26:36 UTC 2026 Modified Files: pkgsrc/lang/ruby: rails.mk Log Message: lang/ruby: update to rails to 7.2.3.1 Make sure to update rails72 to 7.2.3.1. @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (railties-7.2.3.1.gem) = a6f4ebe70f8c25eb19a0fef335212f36893949d1142b099bb812a0d9a8bd56c8 SHA512 (railties-7.2.3.1.gem) = d6acfb9ced88b8b2eb3fb9b8fcc0608522cbef7cb0f492005f83f396950e2e174a8971bc00eff5d37b9469a3799d029347b71d588cbda8a4eff22fcad4d37af5 Size (railties-7.2.3.1.gem) = 182784 bytes @ 1.2 log @www/ruby-rails72: update to 7.2.2.2 Ruby on Rails 7.2.2.2 (2025-08-13) Active Record * Call inspect on ids in RecordNotFound error [CVE-2025-55193] Gannon McGibbon, John Hawthorn Active Storage * Remove dangerous transformations [CVE-2025-24293] Zack Deveau @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.1 2024/12/13 16:55:10 taca Exp $ d3 3 a5 3 BLAKE2s (railties-7.2.2.2.gem) = 6f93fce9cdb4ef68af2862ad158ab7bce09cafee00584babd835178cc383b79f SHA512 (railties-7.2.2.2.gem) = df5fda361d75ba128d6018f025cba22545bbbf9691fe38789aba0934de747ce3037a02feff92ae6876286ecf251b886ec1d290d108e5c6abc8baedc6091d1115 Size (railties-7.2.2.2.gem) = 182784 bytes @ 1.1 log @devel/ruby-railties72: add package version 7.2.2.1 Railties -- Gluing the Engine to the Rails Railties is responsible for gluing all frameworks together. Overall, it: * handles the bootstrapping process for a Rails application; * manages the +rails+ command line interface; * and provides the Rails generators core. @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (railties-7.2.2.1.gem) = 270a38096090fe22e8f60aad31a6dc7e38954953c6ee23ba4153f7af53497f08 SHA512 (railties-7.2.2.1.gem) = b44a6b21bb24a4a8094fb384959315e5db70005621b0a496aeebcd6b59aed37f8dc3d4cf931247e01a84d7cbadd9e8d4bc46fe043c3d42921220872473a48f68 Size (railties-7.2.2.1.gem) = 182784 bytes @