🚨 [security] Update json: 1.8.6 → 2.3.0 (major)#56
Open
depfu[bot] wants to merge 1 commit intomasterfrom
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🚨 Your version of json has known security vulnerabilities 🚨
Advisory: CVE-2020-10663
Disclosed: March 19, 2020
URL: https://www.ruby-lang.org/en/news/2020/03/19/json-dos-cve-2020-10663/
Unsafe Object Creation Vulnerability in JSON (Additional fix)
🚨 We recommend to merge and deploy this update as soon as possible! 🚨
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
✳️ html-proofer (3.7.2 → 3.15.1) · Repo
Release Notes
3.15.0
3.14.0
3.12.0
3.11.0
3.10.0
3.9.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
2.7.0 (from changelog)
2.6.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 44 commits:
bump version and pseudo update changelogMerge pull request #152 from yuki24/add-support-for-CURLPIPE_MULTIPLEXMerge pull request #151 from yuki24/test-against-recent-ruby-versionsAdd support for CURLPIPE_MULTIPLEXTest against MRI 2.5.1, 2.4.4, 2.3.7, 2.2.10, and 2.1.10Merge pull request #141 from atambo/params_encoding_noneMerge pull request #149 from drpump/masterAdded :pipewait curl option.Merge pull request #144 from Rigor/ares_interface_optionsadd dns_interface pass-through optionadd dns_local_ip4 pass-through optionAdd params_encoding :nonebump versionMerge pull request #140 from HappyHax0r/multipart-forcingupdate bundlerfix mime-type specfix mime-types for travis?fix mustermann depremove gemsRSpec tests for multipart properties in options.rbRSpec tests for multipart behavior properties in form.rb and options.rbMore concise syntax for multipart? method.Updating to be a more concise form for the multipart check.Removing the newline.Changes for Ethon to allow multipart-form-data forcing through Typhoeus using "multipart: true" as part of the option set in Request.new().Merge pull request #139 from typhoeus/progressfix issue againfix old ruby issues.fallback to progressfunction for older curlsinclude dltotal and ultotal in testsuse long_longmove onprogressadd correct expactation.show curl versionfixing some annoying warningsfix specsdocsset noprogressmore code and more testsmore code and tests around progressremove debug out and fix specsProgress featureMerge pull request #135 from v-kolesnikov/patch-1Update README.mdRelease Notes
1.12.2 (from changelog)
1.12.1 (from changelog)
1.12.0 (from changelog)
1.11.3 (from changelog)
1.11.2 (from changelog)
1.11.1 (from changelog)
1.11.0 (from changelog)
1.10.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Commits
See the full diff on Github. The new version differs by 10 commits:
version bump to v2.4.0update CHANGELOG in preparation for v2.4.0update dev dependenciesMerge pull request #86 from eagletmt/skip-progress-when-chunkedMerge pull request #87 from halfbyte/patch-1Make version in changelog fit release version.Skip progress report when Content-Length is unavailableupdate test:examples to libiconv 1.15concourse: test most-recent two rubiesconvert to using windows-ruby-dev-tools-releaseRelease Notes
1.10.9
1.10.8
1.10.7
1.10.6
1.10.5
1.10.4
1.10.3
1.10.2
1.10.1
1.10.0
1.9.1
1.9.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
4.0.3 (from changelog)
4.0.2 (from changelog)
4.0.1 (from changelog)
4.0.0 (from changelog)
3.1.1 (from changelog)
3.1.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 38 commits:
Release 4.0.3Welcome 2020CHANGELOG for GH-167Fix 2.7 deprecations and warnings (#168)Update .travis.ymlExperiment with https://keepachangelog.com/Update rubocopRelease 4.0.2Update README.mdCreate SECURITY.mdUpdate CHANGELOG.mdRelease 4.0.1Updated definitionsAdd Tidelift linkCreate FUNDING.ymlTest Ruby 2.7Release 4.0.0Remove support for Ruby < 2.3 in major versionRelease 3.1.1Reinstate support to Ruby 2.1 and 2.2Update PSLFix version in READMERelease 3.1.0Update definitions list (#160)Upgrade to Rubocop 0.70Fix version mismatchMinimum Ruby version is 2.3Upgrade BundlerMake Travis happyFix typo in comment (#159)Fix offensesSwitch to CodeCovUpdate .travis.ymlRelease 3.0.3Update definitions (#154)Fix Rubocop new warningsUpdate .rubocop_defaults.yml (#153)Update docblockCommits
See the full diff on Github. The new version differs by more commits than we can show here.
Sorry, we couldn't find anything useful about this release.
🆕 nokogumbo (added, 2.0.2)
🆕 rainbow (added, 3.0.0)
🗑️ activesupport (removed)
🗑️ colored (removed)
🗑️ i18n (removed)
🗑️ minitest (removed)
🗑️ thread_safe (removed)
🗑️ tzinfo (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands