pkgsrc/lang/ruby
taca 8ec69e9d5d lang/ruby22-base: update to 2.2.10, security release
Ruby 2.2.10 Released				Posted by usa on 28 Mar 2018

Ruby 2.2.10 has been released.  This release includes several security
fixes. Please check the topics below for details.

* CVE-2017-17742: HTTP response splitting in WEBrick
* CVE-2018-8777: DoS by large request in WEBrick
* CVE-2018-6914: Unintentional file and directory creation with directory
  traversal in tempfile and tmpdir
* CVE-2018-8778: Buffer under-read in String#unpack
* CVE-2018-8779: Unintentional socket creation by poisoned NUL byte in
  UNIXServer and UNIXSocket
* CVE-2018-8780: Unintentional directory traversal by poisoned NUL byte in Dir
* Multiple vulnerabilities in RubyGems

Ruby 2.2 is under the state of the security maintenance phase, until the end
of the March of 2018.  After the date, maintenance of Ruby 2.2 will be ended.
So, this release is expected to be the last release of Ruby 2.2.  We will
never make a new release of Ruby 2.2 unless Ruby 2.2.10 has a serious
regression bug.  We recommend you migrating to newer versions of Ruby, such as
2.5.
2018-03-29 03:11:58 +00:00
..
files Update ruby22-base and ruby22 to 2.2.7. 2017-04-09 15:49:50 +00:00
buildlink3.mk Fix indentation in buildlink3.mk files. 2018-01-07 13:03:53 +00:00
DESCR
gem-extract.mk * Split gem-vars.mk and gem-extract.mk from gem.mk. 2015-03-08 14:41:12 +00:00
gem-vars.mk lang/ruby: GC unused variable related to version of Rubygems 2018-02-19 13:48:11 +00:00
gem.mk Remove use of USE_RAKE. 2017-05-30 16:02:25 +00:00
Makefile * Replace RUBY_VERSION_FULL with RUBY_VERSION since there is no 2017-05-30 15:47:51 +00:00
Makefile.common lang/ruby: add "used by" lines for Ruby 2.5 2018-03-13 15:53:23 +00:00
modules.mk lang/ruby: replace RUBY_RAILS_SUPPORTED to RUBY_RAILS_ACCEPTED 2018-03-18 14:21:19 +00:00
platform.mk Disable dtrace on NetBSD arm. Works around an issue observed on earmv7hf 2017-08-29 14:47:35 +00:00
rails.mk lang/ruby: add Ruby on Rails 5.1.5 support 2018-03-21 09:32:48 +00:00
replace.mk Remove use of RUBY_ENCODING_ARG. It was used to specify "-K" option with 2017-04-23 14:16:58 +00:00
rubyversion.mk lang/ruby22-base: update to 2.2.10, security release 2018-03-29 03:11:58 +00:00