2019-10-02 15:39:53 by Takahiro Kambe | Files touched by this commit (4) | |
Log message:
lang/ruby25: update to 2.5.7
Update ruby25-base, ruby25 and ruby25-mode packges to 2.5.7.
pkgsrc chagnes
* fix warnings of pkglint.
Quote from release announce:
Ruby 2.5.7 (2019-10-01)
This release includes security fixes as listed below. Please check the
topics below for details.
* CVE-2019-16255: A code injection vulnerability of Shell#[] and Shell#test
* CVE-2019-16254: HTTP response splitting in WEBrick (Additional fix)
* CVE-2019-15845: A NUL injection vulnerability of File.fnmatch and
File.fnmatch?
* CVE-2019-16201: Regular Expression Denial of Service vulnerability of
WEBrick's Digest access authentication
|
2019-08-28 16:12:22 by Takahiro Kambe | Files touched by this commit (3) | |
Log message:
lang/ruby25: update to 2.5.6
Update ruby25-base/ruby25 to 2.5.6.
Ruby 2.5.6 (2019-08-28)
Ruby 2.5.6 has been released.
This release includes about 40 bug fixes after the previous release, and also \
includes a security fix. Please check the topics below for details.
* Multiple jQuery vulnerabilities in RDoc
See the commit log for details.
|
2019-03-16 15:34:56 by Takahiro Kambe | Files touched by this commit (3) | |
Log message:
lang/ruby25-base: updateo to 2.5.5
Update ruby25{,-base} to 2.5.5.
Quote from release announce:
Ruby 2.5.4 (2019-03-13)
This release includes bug fixes and a security update of the bundled
RubyGems. See details in Multiple vulnerabilities in RubyGems and the commit
logs.
Ruby 2.5.5 (2019-03-15)
This release includes a bug fix for the deadlock in the
multi-thread+multi-process (using Process.fork) applications (ex: puma).
|
2019-03-12 05:22:34 by Takahiro Kambe | Files touched by this commit (2) |
Log message:
lang/ruby25-base: Add security patch for rubygems
Add security patch for rubygems, fixing these problem.
* CVE-2019-8320: Delete directory using symlink when decompressing tar
* CVE-2019-8321: Escape sequence injection vulnerability in verbose
* CVE-2019-8322: Escape sequence injection vulnerability in gem owner
* CVE-2019-8323: Escape sequence injection vulnerability in API response handlin
g
* CVE-2019-8324: Installing a malicious gem may lead to arbitrary code execution
* CVE-2019-8325: Escape sequence injection vulnerability in errors
https://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems/
Since original patch included in official announce dose not cleanly applied to
Ruby 2.5.3, use a local version which drop patch to none existing test.
Bump PKGREVISION.
|
2019-02-14 07:03:50 by Takahiro Kambe | Files touched by this commit (2) |
Log message:
lang/ruby25-base: add missing document installation
* Add missing document installation.
* Do not remove non-existing extconf.rb of ext/tk.
Bump PKGREVISION.
|
2019-02-07 11:07:21 by matthew green | Files touched by this commit (3) |
Log message:
apply the gcc6.5 and arm64 hack to gcc [67].*. fixes arm64 builds on gcc7.
|
2019-01-03 06:19:03 by Takahiro Kambe | Files touched by this commit (5) |
Log message:
lang/ruby: switch to use distfiles in '.xz' format
Switch to use distfiles in '.xz' format.
|
2018-12-22 04:53:24 by Roy Marples | Files touched by this commit (1) |
Log message:
ruby does not like -fomit-frame-pointer on NetBSD/aarch64
|
2018-10-18 16:21:36 by Takahiro Kambe | Files touched by this commit (2) | |
Log message:
lang/ruby25-base: update to 2.5.3
Ruby 2.5.2 Released
Ruby 2.5.2 has been released.
This release includes some bug fixes and some security fixes.
* CVE-2018-16396: Tainted flags are not propagated in Array#pack and
String#unpack with some directives
* CVE-2018-16395: OpenSSL::X509::Name equality check does not work correctly
There are also some bug fixes. See commit logs for more details.
Ruby 2.5.3 Released
Ruby 2.5.3 has been released.
There were some missing files in the release packages of 2.5.2 which are
necessary for building. See details in [Bug #15232].
This release is just for fixing the packaging issue. This release doesn’t
contain any additional bug fixes from 2.5.2.
|
2018-07-17 12:56:24 by Jonathan Perkin | Files touched by this commit (8) |
Log message:
*: Add some required USE_GCC_RUNTIME.
|