π¨ [security] [ruby] Update rails 7.2.3 β 8.0.3 (major)#2583
π¨ [security] [ruby] Update rails 7.2.3 β 8.0.3 (major)#2583StephenHulme merged 8 commits intodevelopfrom
Conversation
3f07519 to
cfcac2b
Compare
cfcac2b to
55c6266
Compare
|
@βdepfu rebase |
55c6266 to
6ee05bd
Compare
6ee05bd to
6e07262
Compare
6e07262 to
b9b6cf8
Compare
Can change response from 500 to 400 when handling invalid parameters
Codecov Reportβ
All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #2583 +/- ##
========================================
Coverage 84.98% 84.98%
========================================
Files 504 504
Lines 20667 20667
Branches 377 377
========================================
Hits 17564 17564
Misses 3100 3100
Partials 3 3
Flags with carried forward coverage won't be shown. Click here to find out more. β View full report in Codecov by Sentry. π New features to boost your workflow:
|
BenTopping
left a comment
There was a problem hiding this comment.
Changes look sane to me, haven't tested locally.
| config.sequencescape_url = 'http://localhost:3000' | ||
|
|
||
| # is this used? no reference in Limber | ||
| config.qc_submission_name = 'MiSeq for QC' |
There was a problem hiding this comment.
Looks like these are also in the deployment project so can be removed there too.
There was a problem hiding this comment.
Ah yes, I think there's another PR for that - thanks for reminding me: https://github.com/sanger/deployment/pull/839
|
Thanks for the review - will run it through int-suite tomorrow π |
|
Int-suite passed, will merge in shortly |
Deployment project changes: https://github.com/sanger/deployment/pull/839
π¨ Your current dependencies have known security vulnerabilities π¨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
β³οΈ rails (7.2.3 β 8.0.3) Β· Repo Β· Changelog
Release Notes
8.0.3
8.0.2.1
8.0.2
8.0.1
8.0.0.1
8.0.0
7.2.3.1
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Security Advisories π¨
π¨ Possible Content Security Policy bypass in Action Dispatch
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Security Advisories π¨
π¨ Rails has a possible XSS vulnerability in its Action View tag helpers
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Security Advisories π¨
π¨ Active Record logging vulnerable to ANSI escape injection
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Security Advisories π¨
π¨ Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
π¨ Rails Active Storage has possible content type bypass via metadata in direct uploads
π¨ Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
π¨ Rails Active Storage has possible Path Traversal in DiskService
π¨ Rails Active Storage has possible glob injection in its DiskService
π¨ Active Storage allowed transformation methods that were potentially unsafe
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Security Advisories π¨
π¨ Rails Active Support has a possible ReDoS vulnerability in number_to_delimited
π¨ Rails Active Support has a possible XSS vulnerability in SafeBuffer#%
π¨ Rails Active Support has a possible DoS vulnerability in its number helpers
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
0.6.3
0.6.2
0.6.1
0.6.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
8.0.1 (from changelog)
8.0.0.1 (from changelog)
8.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
0.6.1
0.6.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
π uri (added, 1.1.1)
ποΈ cgi (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands