Subject: CVS commit: pkgsrc/misc/rubygems
From: Takahiro Kambe
Date: 2011-09-04 19:05:13
Message id: 20110904170513.C9E1C175DD@cvs.netbsd.org

Log Message:
Update rubygems package to 1.8.10.

=== 1.8.10 / 2011-08-25

RubyGems 1.8.10 contains a security fix that prevents malicious gems from
executing code when their specification is loaded.  See
https://github.com/rubygems/rubygems/pull/165 for details.

* 5 bug fixes:

  * RubyGems escapes strings in ruby-format specs using #dump instead of #to_s
    and %q to prevent code injection.  Issue #165 by Postmodern
  * RubyGems attempt to activate the psych gem now to obtain bugfixes from
    psych.
  * Gem.dir has been restored to the front of Gem.path.  Fixes remaining
    problem with Issue #115
  * Fixed Syck DefaultKey infecting ruby-format specifications.
  * `gem uninstall a b` no longer stops if gem "a" is not installed.

Files:
RevisionActionfile
1.41modifypkgsrc/misc/rubygems/Makefile
1.31modifypkgsrc/misc/rubygems/distinfo
1.11modifypkgsrc/misc/rubygems/patches/patch-aa