diff options
author | sbd <sbd> | 2012-08-20 08:19:36 +0000 |
---|---|---|
committer | sbd <sbd> | 2012-08-20 08:19:36 +0000 |
commit | a3490635e097ae6187565d2964a53648159df645 (patch) | |
tree | 9214954fc7718c523260b27e5bcdd6c8e03d72d8 | |
parent | 51a622c60111da3d312e5cc3f1483f5dd5b2c4ee (diff) | |
download | pkgsrc-a3490635e097ae6187565d2964a53648159df645.tar.gz |
Pullup ticket #3902 - requested by taca
Ruby on Rails 3.1.8 security update
Revisions pulled up:
- databases/ruby-activerecord31/distinfo 1.6
- devel/ruby-activemodel31/distinfo 1.6
- devel/ruby-activesupport31/distinfo 1.7
- devel/ruby-railties31/distinfo 1.6
- lang/ruby/rails.mk 1.29
- mail/ruby-actionmailer31/distinfo 1.6
- www/ruby-actionpack31/distinfo 1.7
- www/ruby-activeresource31/distinfo 1.6
- www/ruby-rails31/distinfo 1.6
---
Module Name: pkgsrc
Committed By: taca
Date: Sun Aug 12 10:32:52 UTC 2012
Modified Files:
pkgsrc/lang/ruby: rails.mk
Log Message:
Start Ruby on Rails 3.1.8.
---
Module Name: pkgsrc
Committed By: taca
Date: Sun Aug 12 10:33:18 UTC 2012
Modified Files:
pkgsrc/devel/ruby-activesupport31: distinfo
Log Message:
Update ruby-activesupport31 to 3.1.8.
## Rails 3.1.8 (Aug 9, 2012)
* No changes.
---
Module Name: pkgsrc
Committed By: taca
Date: Sun Aug 12 10:33:48 UTC 2012
Modified Files:
pkgsrc/devel/ruby-activemodel31: distinfo
Log Message:
Update ruby-activemodel31 to 3.1.8.
## Rails 3.1.8 (Aug 9, 2012)
* No changes.
---
Module Name: pkgsrc
Committed By: taca
Date: Sun Aug 12 10:34:38 UTC 2012
Modified Files:
pkgsrc/www/ruby-actionpack31: distinfo
Log Message:
Update ruby-actionpack31 to 3.1.8.
## Rails 3.1.8 (Aug 9, 2012)
* There is an XSS vulnerability in the strip_tags helper in Ruby on Rails, the
helper doesn't correctly handle malformed html. As a result an attacker can
execute arbitrary javascript through the use of specially crafted malformed
html.
*Marek from Nethemba (www.nethemba.com) & Santiago Pastorino*
* When a "prompt" value is supplied to the `select_tag` helper, the
"prompt" value is not escaped.
If untrusted data is not escaped, and is supplied as the prompt value,
there is a potential for XSS attacks.
Vulnerable code will look something like this:
select_tag("name", options, :prompt => UNTRUSTED_INPUT)
*Santiago Pastorino*
---
Module Name: pkgsrc
Committed By: taca
Date: Sun Aug 12 10:35:20 UTC 2012
Modified Files:
pkgsrc/databases/ruby-activerecord31: distinfo
Log Message:
Update ruby-activerecord31 to 3.1.8.
## Rails 3.1.8 (Aug 9, 2012)
* No changes.
---
Module Name: pkgsrc
Committed By: taca
Date: Sun Aug 12 10:36:35 UTC 2012
Modified Files:
pkgsrc/www/ruby-activeresource31: distinfo
Log Message:
Update ruby-activeresource31 to 3.1.8.
## Rails 3.1.8 (Aug 9, 2012)
* No changes.
---
Module Name: pkgsrc
Committed By: taca
Date: Sun Aug 12 10:37:22 UTC 2012
Modified Files:
pkgsrc/mail/ruby-actionmailer31: distinfo
Log Message:
Update ruby-actionmailer31 to 3.1.8.
## Rails 3.1.8 (Aug 9, 2012)
* No changes.
---
Module Name: pkgsrc
Committed By: taca
Date: Sun Aug 12 10:37:52 UTC 2012
Modified Files:
pkgsrc/devel/ruby-railties31: distinfo
Log Message:
Update ruby-railties31 to 3.1.8.
## Rails 3.1.8 (Aug 9, 2012)
* No changes.
---
Module Name: pkgsrc
Committed By: taca
Date: Sun Aug 12 10:38:45 UTC 2012
Modified Files:
pkgsrc/www/ruby-rails31: distinfo
Log Message:
Update ruby-rails31 to 3.1.8.
This is a meta-like package and no changes.
-rw-r--r-- | databases/ruby-activerecord31/distinfo | 8 | ||||
-rw-r--r-- | devel/ruby-activemodel31/distinfo | 8 | ||||
-rw-r--r-- | devel/ruby-activesupport31/distinfo | 8 | ||||
-rw-r--r-- | devel/ruby-railties31/distinfo | 8 | ||||
-rw-r--r-- | lang/ruby/rails.mk | 4 | ||||
-rw-r--r-- | mail/ruby-actionmailer31/distinfo | 8 | ||||
-rw-r--r-- | www/ruby-actionpack31/distinfo | 8 | ||||
-rw-r--r-- | www/ruby-activeresource31/distinfo | 8 | ||||
-rw-r--r-- | www/ruby-rails31/distinfo | 8 |
9 files changed, 34 insertions, 34 deletions
diff --git a/databases/ruby-activerecord31/distinfo b/databases/ruby-activerecord31/distinfo index 40ac06e7c46..183f4dff186 100644 --- a/databases/ruby-activerecord31/distinfo +++ b/databases/ruby-activerecord31/distinfo @@ -1,5 +1,5 @@ -$NetBSD: distinfo,v 1.4.2.1 2012/08/12 14:26:14 tron Exp $ +$NetBSD: distinfo,v 1.4.2.2 2012/08/20 08:19:36 sbd Exp $ -SHA1 (activerecord-3.1.7.gem) = 4cf03c16d68a8d9ba05c9b156384ce0d37f84952 -RMD160 (activerecord-3.1.7.gem) = 1e40052112da6556fbbdf3e9ce2562de3e0ac2e9 -Size (activerecord-3.1.7.gem) = 377856 bytes +SHA1 (activerecord-3.1.8.gem) = d333c56b4115c8ab1f8ee4e4d2a0207890924ecf +RMD160 (activerecord-3.1.8.gem) = 30a7ef220741698764cef7a3382972bcb524f436 +Size (activerecord-3.1.8.gem) = 377856 bytes diff --git a/devel/ruby-activemodel31/distinfo b/devel/ruby-activemodel31/distinfo index 62f8cd7fc17..15e0254181c 100644 --- a/devel/ruby-activemodel31/distinfo +++ b/devel/ruby-activemodel31/distinfo @@ -1,5 +1,5 @@ -$NetBSD: distinfo,v 1.4.2.1 2012/08/12 14:26:14 tron Exp $ +$NetBSD: distinfo,v 1.4.2.2 2012/08/20 08:19:36 sbd Exp $ -SHA1 (activemodel-3.1.7.gem) = b9829abd14e55d7b27c232ec50760350690cc31d -RMD160 (activemodel-3.1.7.gem) = 95f91f6af5a8a7b9ff5c101c3730c646198d0091 -Size (activemodel-3.1.7.gem) = 41984 bytes +SHA1 (activemodel-3.1.8.gem) = c8524f4d849fba3251b013ad4b2dcc4e71d84bd2 +RMD160 (activemodel-3.1.8.gem) = 25037edd1d32fa73505b7a2f5271a3c575f79c42 +Size (activemodel-3.1.8.gem) = 41984 bytes diff --git a/devel/ruby-activesupport31/distinfo b/devel/ruby-activesupport31/distinfo index 83fe5b06bc0..0de774b6e66 100644 --- a/devel/ruby-activesupport31/distinfo +++ b/devel/ruby-activesupport31/distinfo @@ -1,5 +1,5 @@ -$NetBSD: distinfo,v 1.5.2.1 2012/08/12 14:26:14 tron Exp $ +$NetBSD: distinfo,v 1.5.2.2 2012/08/20 08:19:36 sbd Exp $ -SHA1 (activesupport-3.1.7.gem) = b3577252695f2ffb3b001d67f99f81e292dc31ee -RMD160 (activesupport-3.1.7.gem) = 0e904360e1e472c201830c80dab8fa6f655161db -Size (activesupport-3.1.7.gem) = 307712 bytes +SHA1 (activesupport-3.1.8.gem) = d884ed4cb183108531a5e78d93f8d24bf265640a +RMD160 (activesupport-3.1.8.gem) = 41e635c73061048748c28ce531fddad701ddc0f6 +Size (activesupport-3.1.8.gem) = 307712 bytes diff --git a/devel/ruby-railties31/distinfo b/devel/ruby-railties31/distinfo index 130df9dc281..e4a164a5527 100644 --- a/devel/ruby-railties31/distinfo +++ b/devel/ruby-railties31/distinfo @@ -1,5 +1,5 @@ -$NetBSD: distinfo,v 1.4.2.1 2012/08/12 14:26:14 tron Exp $ +$NetBSD: distinfo,v 1.4.2.2 2012/08/20 08:19:36 sbd Exp $ -SHA1 (railties-3.1.7.gem) = 8992fc16a79a2eb655afe5d3adffa7829b590634 -RMD160 (railties-3.1.7.gem) = 2c5e8e96526e187d5d400c4409b5551c0b931a77 -Size (railties-3.1.7.gem) = 1549824 bytes +SHA1 (railties-3.1.8.gem) = b86d7841ce26d8a4b7ca8e5f7823ca30d6f28a0f +RMD160 (railties-3.1.8.gem) = 2c6dca6c246d961ea8d32f99041d67b0ac9ea673 +Size (railties-3.1.8.gem) = 1549824 bytes diff --git a/lang/ruby/rails.mk b/lang/ruby/rails.mk index 5b50c03804b..6256d9defab 100644 --- a/lang/ruby/rails.mk +++ b/lang/ruby/rails.mk @@ -1,4 +1,4 @@ -# $NetBSD: rails.mk,v 1.24.2.4 2012/08/20 07:54:05 sbd Exp $ +# $NetBSD: rails.mk,v 1.24.2.5 2012/08/20 08:19:36 sbd Exp $ .if !defined(_RUBY_RAILS_MK) _RUBY_RAILS_MK= # defined @@ -39,7 +39,7 @@ _RUBY_RAILS_MK= # defined # current Ruby on Rails versions. # RUBY_RAILS3_VERSION?= 3.0.17 -RUBY_RAILS31_VERSION?= 3.1.7 +RUBY_RAILS31_VERSION?= 3.1.8 RUBY_RAILS32_VERSION?= 3.2.7 RUBY_RAILS_SUPPORTED?= # defined diff --git a/mail/ruby-actionmailer31/distinfo b/mail/ruby-actionmailer31/distinfo index 6470e10b49e..b05d2b1580d 100644 --- a/mail/ruby-actionmailer31/distinfo +++ b/mail/ruby-actionmailer31/distinfo @@ -1,5 +1,5 @@ -$NetBSD: distinfo,v 1.4.2.1 2012/08/12 14:26:14 tron Exp $ +$NetBSD: distinfo,v 1.4.2.2 2012/08/20 08:19:36 sbd Exp $ -SHA1 (actionmailer-3.1.7.gem) = bad4d4c1a9ada68d1cceb632fb2d7e348fef6a24 -RMD160 (actionmailer-3.1.7.gem) = 4553fb5619f81f520aad47adef04d4a5f2821fbf -Size (actionmailer-3.1.7.gem) = 30208 bytes +SHA1 (actionmailer-3.1.8.gem) = de69b149b947d76cd4a8cafbc8dd4b51d15a9373 +RMD160 (actionmailer-3.1.8.gem) = 9c79a4f57c1f0d31c7c669c2965bb60b5ef7c680 +Size (actionmailer-3.1.8.gem) = 30208 bytes diff --git a/www/ruby-actionpack31/distinfo b/www/ruby-actionpack31/distinfo index e49b63400dc..c2249c1c309 100644 --- a/www/ruby-actionpack31/distinfo +++ b/www/ruby-actionpack31/distinfo @@ -1,5 +1,5 @@ -$NetBSD: distinfo,v 1.5.2.1 2012/08/12 14:26:14 tron Exp $ +$NetBSD: distinfo,v 1.5.2.2 2012/08/20 08:19:36 sbd Exp $ -SHA1 (actionpack-3.1.7.gem) = d6d7d99e6b4c30f80ca5a1d321f44aefeb5583cf -RMD160 (actionpack-3.1.7.gem) = b49e3389c06c965c43aeb3a18893bcd44bd5797b -Size (actionpack-3.1.7.gem) = 367616 bytes +SHA1 (actionpack-3.1.8.gem) = 20d22f75b553e897808269ad308405570d2c874b +RMD160 (actionpack-3.1.8.gem) = 9343ed89627b3a9dd6d4eca3d82a9d66fae09853 +Size (actionpack-3.1.8.gem) = 368128 bytes diff --git a/www/ruby-activeresource31/distinfo b/www/ruby-activeresource31/distinfo index c169f164338..ce332c7495f 100644 --- a/www/ruby-activeresource31/distinfo +++ b/www/ruby-activeresource31/distinfo @@ -1,5 +1,5 @@ -$NetBSD: distinfo,v 1.4.2.1 2012/08/12 14:26:15 tron Exp $ +$NetBSD: distinfo,v 1.4.2.2 2012/08/20 08:19:36 sbd Exp $ -SHA1 (activeresource-3.1.7.gem) = cd2e8ae08db6b289084802b52a19bebcaaf3a6ce -RMD160 (activeresource-3.1.7.gem) = 94a878f59406ca4d8b117c4a7f54f6cb0ab91e2c -Size (activeresource-3.1.7.gem) = 36352 bytes +SHA1 (activeresource-3.1.8.gem) = aa7593702ade6b4bdf7b2db5cb9318915533894b +RMD160 (activeresource-3.1.8.gem) = c35e5d27b7c34cc3847d5ea8663b822ffa66314e +Size (activeresource-3.1.8.gem) = 36864 bytes diff --git a/www/ruby-rails31/distinfo b/www/ruby-rails31/distinfo index ea2ed1bac82..0ed1ec4a76d 100644 --- a/www/ruby-rails31/distinfo +++ b/www/ruby-rails31/distinfo @@ -1,5 +1,5 @@ -$NetBSD: distinfo,v 1.4.2.1 2012/08/12 14:26:15 tron Exp $ +$NetBSD: distinfo,v 1.4.2.2 2012/08/20 08:19:37 sbd Exp $ -SHA1 (rails-3.1.7.gem) = a0e428916d71574c1b2f2c0c1c1b7338fb714449 -RMD160 (rails-3.1.7.gem) = c2e26596d670974dd830793150e16888cfc95035 -Size (rails-3.1.7.gem) = 3584 bytes +SHA1 (rails-3.1.8.gem) = 1d830ef845c5600eeb947cb32158bde8af1cf7f8 +RMD160 (rails-3.1.8.gem) = c4be33a6e2fb0124041edc79123231492d81d4e6 +Size (rails-3.1.8.gem) = 3584 bytes |