pkgsrc/www/ruby-actionpack60/distinfo
taca efabc36003 www/ruby-rails60: update to 6.0.3.7
Real changes are in www/ruby-actionpack60 only.

## Rails 6.0.3.7 (May 05, 2021) ##

*   Prevent catastrophic backtracking during mime parsing
    CVE-2021-22902

*   Prevent regex DoS in HTTP token authentication
    CVE-2021-22904

*   Prevent string polymorphic route arguments.

    `url_for` supports building polymorphic URLs via an array
    of arguments (usually symbols and records). If a developer passes a
    user input array, strings can result in unwanted route helper calls.

    CVE-2021-22885

    *Gannon McGibbon*
2021-05-08 14:02:33 +00:00

6 lines
412 B
Text

$NetBSD: distinfo,v 1.9 2021/05/08 14:02:33 taca Exp $
SHA1 (actionpack-6.0.3.7.gem) = 49825023b27228b23d08fa2022e6ac220f07363e
RMD160 (actionpack-6.0.3.7.gem) = 646b527c0a387635c28839292f19591d77da793f
SHA512 (actionpack-6.0.3.7.gem) = 2285e4ed9e2424403f0221bb17fafdc7bc19e4e810bb522616de56bf79edd767341d91f34736361590ce99d26425ad27d020c872dd576827e000c795a2d2fca5
Size (actionpack-6.0.3.7.gem) = 217600 bytes