Path to this page:
Subject: CVS commit: [pkgsrc-2012Q4] pkgsrc
From: Matthias Scheler
Date: 2013-01-18 16:08:39
Message id: 20130118150839.9D5C9175DD@cvs.netbsd.org
Log Message:
Pullup ticket #4024 - requested by taca
databases/ruby-activerecord31: security update
devel/ruby-activemodel31: security update
devel/ruby-activesupport31: security update
devel/ruby-railties31: security update
mail/ruby-actionmailer31: security update
www/ruby-actionpack31: security update
www/ruby-activeresource31: security update
www/ruby-rails31: security update
Revisions pulled up:
- databases/ruby-activerecord31/distinfo 1.8
- devel/ruby-activemodel31/distinfo 1.8
- devel/ruby-activesupport31/distinfo 1.9
- devel/ruby-railties31/distinfo 1.8
- lang/ruby/rails.mk 1.36
- mail/ruby-actionmailer31/distinfo 1.8
- www/ruby-actionpack31/distinfo 1.9
- www/ruby-activeresource31/distinfo 1.8
- www/ruby-rails31/distinfo 1.8
---
Module Name: pkgsrc
Committed By: taca
Date: Wed Jan 9 12:33:28 UTC 2013
Modified Files:
pkgsrc/lang/ruby: rails.mk
Log Message:
Start update of Ruby on Rails 3.1.10.
---
Module Name: pkgsrc
Committed By: taca
Date: Wed Jan 9 12:34:08 UTC 2013
Modified Files:
pkgsrc/devel/ruby-activesupport31: distinfo
Log Message:
Update ruby-activesupport31 to 3.1.10.
## Rails 3.1.10 (Jan 8, 2012) ##
* Hash.from_xml raises when it encounters type="symbol" or \
type="yaml".
Use Hash.from_trusted_xml to parse this XML.
CVE-2013-0156
*Jeremy Kemper*
---
Module Name: pkgsrc
Committed By: taca
Date: Wed Jan 9 12:34:55 UTC 2013
Modified Files:
pkgsrc/devel/ruby-activemodel31: distinfo
Log Message:
Update ruby-activemodel31 to 3.1.10.
Only version has updated.
---
Module Name: pkgsrc
Committed By: taca
Date: Wed Jan 9 12:35:24 UTC 2013
Modified Files:
pkgsrc/www/ruby-activeresource31: distinfo
Log Message:
Update ruby-activeresource31 to 3.1.10.
Only version has updated.
---
Module Name: pkgsrc
Committed By: taca
Date: Wed Jan 9 12:36:36 UTC 2013
Modified Files:
pkgsrc/databases/ruby-activerecord31: distinfo
Log Message:
Update ruby-activerecord31 to 3.1.10.
## Rails 3.1.10
* Fix querying with an empty hash *Damien Mathieu* [CVE-2013-0155]
---
Module Name: pkgsrc
Committed By: taca
Date: Wed Jan 9 12:37:05 UTC 2013
Modified Files:
pkgsrc/www/ruby-actionpack31: distinfo
Log Message:
Update ruby-actionpack31 to 3.1.10.
## Rails 3.1.10
* Strip nils from collections on JSON and XML posts. [CVE-2013-0155]
---
Module Name: pkgsrc
Committed By: taca
Date: Wed Jan 9 12:37:52 UTC 2013
Modified Files:
pkgsrc/mail/ruby-actionmailer31: distinfo
Log Message:
Update ruby-actionpack31 to 3.1.10.
Only version has updated.
---
Module Name: pkgsrc
Committed By: taca
Date: Wed Jan 9 12:38:11 UTC 2013
Modified Files:
pkgsrc/devel/ruby-railties31: distinfo
Log Message:
Update ruby-railties31 to 3.1.10.
Only version has updated.
---
Module Name: pkgsrc
Committed By: taca
Date: Wed Jan 9 12:38:29 UTC 2013
Modified Files:
pkgsrc/www/ruby-rails31: distinfo
Log Message:
Update ruby-rails31 to 3.1.10.
Only version has updated.
Files: