Subject: CVS commit: [pkgsrc-2021Q4] pkgsrc
From: Benny Siegert
Date: 2022-03-03 20:06:04
Message id: 20220303190604.6A0ADFB24@cvs.NetBSD.org

Log Message:
Pullup ticket #6588 - requested by taca
www/ruby-rails60: security fix

Revisions pulled up:
- databases/ruby-activerecord60/distinfo                        1.15
- devel/ruby-activejob60/distinfo                               1.15
- devel/ruby-activemodel60/distinfo                             1.15
- devel/ruby-activestorage60/distinfo                           1.15
- devel/ruby-activesupport60/distinfo                           1.15
- devel/ruby-railties60/distinfo                                1.15
- lang/ruby/rails.mk                                            1.112
- mail/ruby-actionmailbox60/distinfo                            1.15
- mail/ruby-actionmailer60/distinfo                             1.15
- textproc/ruby-actiontext60/distinfo                           1.15
- www/ruby-actioncable60/distinfo                               1.15
- www/ruby-actionpack60/distinfo                                1.15
- www/ruby-actionview60/distinfo                                1.15
- www/ruby-rails60/distinfo                                     1.15

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sun Feb 13 07:31:23 UTC 2022

   Modified Files:
   	pkgsrc/databases/ruby-activerecord60: distinfo
   	pkgsrc/devel/ruby-activejob60: distinfo
   	pkgsrc/devel/ruby-activemodel60: distinfo
   	pkgsrc/devel/ruby-activestorage60: distinfo
   	pkgsrc/devel/ruby-activesupport60: distinfo
   	pkgsrc/devel/ruby-railties60: distinfo
   	pkgsrc/lang/ruby: rails.mk
   	pkgsrc/mail/ruby-actionmailbox60: distinfo
   	pkgsrc/mail/ruby-actionmailer60: distinfo
   	pkgsrc/textproc/ruby-actiontext60: distinfo
   	pkgsrc/www/ruby-actioncable60: distinfo
   	pkgsrc/www/ruby-actionpack60: distinfo
   	pkgsrc/www/ruby-actionview60: distinfo
   	pkgsrc/www/ruby-rails60: distinfo

   Log Message:
   www/ruby-rails60: update to  6.0.4.6

   This update contains security fix for CVE-2022-23633 in ruby-actionpack60.

   Active Support 6.0.4.6 (2022-02-11)

   * Fix Reloader method signature to work with the new Executor signature.

   Action Pack 6.0.4.6

   6.0.4.5 (2022-02-11)

   * Under certain circumstances, the middleware isn't informed that the
     response body has been fully closed which result in request state
     not being fully reset before the next request.

     [CVE-2022-23633]

   Other packages have no change.

Files:
RevisionActionfile
1.14.2.1modifypkgsrc/databases/ruby-activerecord60/distinfo
1.14.2.1modifypkgsrc/devel/ruby-activejob60/distinfo
1.14.2.1modifypkgsrc/devel/ruby-activemodel60/distinfo
1.14.2.1modifypkgsrc/devel/ruby-activestorage60/distinfo
1.14.2.1modifypkgsrc/devel/ruby-activesupport60/distinfo
1.14.2.1modifypkgsrc/devel/ruby-railties60/distinfo
1.109.2.2modifypkgsrc/lang/ruby/rails.mk
1.14.2.1modifypkgsrc/mail/ruby-actionmailbox60/distinfo
1.14.2.1modifypkgsrc/mail/ruby-actionmailer60/distinfo
1.14.2.1modifypkgsrc/textproc/ruby-actiontext60/distinfo
1.14.2.1modifypkgsrc/www/ruby-actioncable60/distinfo
1.14.2.1modifypkgsrc/www/ruby-actionpack60/distinfo
1.14.2.1modifypkgsrc/www/ruby-actionview60/distinfo
1.14.2.1modifypkgsrc/www/ruby-rails60/distinfo