1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349
|
rails (2:4.2.7.1-1+deb9u2) stretch; urgency=high
* Team upload.
* Add patch to fix possible XSS vector in JS escape helper.
(Fixes: CVE-2020-5267) (Closes: #954304)
-- Utkarsh Gupta <utkarsh@debian.org> Sun, 22 Mar 2020 18:05:32 +0530
rails (2:4.2.7.1-1+deb9u1) stretch; urgency=medium
* CVE-2018-16476 (Closes: #914847)
* CVE-2019-5418 / CVE-2019-5419 (Closes: #924520)
-- Moritz Mühlenhoff <jmm@debian.org> Thu, 18 Apr 2019 20:48:13 +0200
rails (2:4.2.7.1-1) unstable; urgency=medium
* New upstream release; includes fixes for the following issues:
- CVE-2016-6317: unsafe query generation in Active Record (Closes: #834154)
- CVE-2016-6316: Possible XSS Vulnerability in Action View (Closes: #834155)
* debian/watch: restrict to the 4.x series for now
-- Antonio Terceiro <terceiro@debian.org> Mon, 22 Aug 2016 14:33:48 -0300
rails (2:4.2.6-2) unstable; urgency=medium
* Team upload
* ruby-rails: Add ruby-coffee-rails to recommends (Closes: #818470)
* Relax ruby-json (drop << 2.0 requirement)
-- Pirate Praveen <praveen@debian.org> Fri, 22 Jul 2016 23:37:44 +0530
rails (2:4.2.6-1) unstable; urgency=medium
[ Antonio Terceiro ]
* New upstream release
* debian/clean: list files that are created when the tests run
* Drop 0003-Make-AR-SpawnMethods-merge-to-check-an-arg-is-a-Proc.patch,
applied upstream
[ Praveen Arimbrathodiyil ]
* Set minimum version of ruby-sprockets-rails (for sprockets version
incompatibility with ruby-sass-rails)
-- Antonio Terceiro <terceiro@debian.org> Sat, 09 Apr 2016 19:39:46 -0300
rails (2:4.2.5.2-2) unstable; urgency=medium
[ Cédric Boutillier ]
* Remove version in the gem2deb build-dependency
* Use https:// in Vcs-* fields
* Bump Standards-Version to 3.9.7 (no changes needed)
* Run wrap-and-sort on packaging files
[ Antonio Terceiro ]
* 0002-load_paths.rb-don-t-load-bundler.patch: don't load bundler when
running tests
* Run tests during build
- add all runtime dependencies as build dependencies as well
* Run unit tests also under autopkgtest
* Add 0003-Make-AR-SpawnMethods-merge-to-check-an-arg-is-a-Proc.patch to fix
ActiveRecord relations with Ruby 2.3
* 0004-ActiveRecord-skip-a-few-tests-that-are-broken-on-Deb.patch skip some
tests that are broken on Debian.
-- Antonio Terceiro <terceiro@debian.org> Fri, 04 Mar 2016 14:49:00 -0300
rails (2:4.2.5.2-1) unstable; urgency=high
* New upstream release
* Fixes 2 security issues:
- [CVE-2016-2098] Possible remote code execution vulnerability in Action
Pack
- [CVE-2016-2097] Possible Information Leak Vulnerability in Action View.
-- Antonio Terceiro <terceiro@debian.org> Wed, 02 Mar 2016 11:50:02 -0300
rails (2:4.2.5.1-2) unstable; urgency=medium
* ruby-rails: change dependency from bundler to ruby-bundler, which will
not pull a development toolchain in Recommends:.
* Switch Vcs-* to https URLs
-- Antonio Terceiro <terceiro@debian.org> Sun, 21 Feb 2016 13:58:35 -0300
rails (2:4.2.5.1-1) unstable; urgency=high
* New upstream release. Includes fixes for the following several security
issues:
- [CVE-2015-7576] Timing attack vulnerability in basic authentication in
Action Controller.
- [CVE-2016-0751] Possible Object Leak and Denial of Service attack in
Action Pack
- [CVE-2015-7577] Nested attributes rejection proc bypass in Active Record.
- [CVE-2016-0752] Possible Information Leak Vulnerability in Action View
- [CVE-2016-0753] Possible Input Validation Circumvention in Active Model
- [CVE-2015-7581] Object leak vulnerability for wildcard controller routes
in Action Pack
-- Antonio Terceiro <terceiro@debian.org> Thu, 28 Jan 2016 10:56:35 -0200
rails (2:4.2.5-1) unstable; urgency=medium
* New upstream release
* Skip dependency resolution check during the build, because too many of the
dependencies of the binary packages depend on rails to build, so let's
avoid loops. The checks are still performed as part of autopkgtest tests,
anyway.
-- Antonio Terceiro <terceiro@debian.org> Mon, 14 Dec 2015 11:04:15 -0200
rails (2:4.2.4-2) unstable; urgency=medium
* Upload to unstable
-- Antonio Terceiro <terceiro@debian.org> Sat, 12 Dec 2015 16:24:01 -0200
rails (2:4.2.4-1) experimental; urgency=medium
* Team upload
* New upstream patch release
* Set minimum version for ruby-coffee-rails to 4.1.0
-- Pirate Praveen <praveen@debian.org> Tue, 15 Sep 2015 18:25:16 +0530
rails (2:4.2.3-4) experimental; urgency=medium
* Team upload
* ruby-activesupport: requires ruby-thread-safe >= 0.3.4, ruby-i18n >= 0.7
* ruby-actionview: requires ruby-html-sanitizer and ruby-dom-testing
* Check dependencies mentioned in gemspec
-- Pirate Praveen <praveen@debian.org> Thu, 20 Aug 2015 11:50:37 +0530
rails (2:4.2.3-3) experimental; urgency=medium
* ruby-actionmailer: Depends: ruby-activejob
* ruby-rails: requires ruby-turbolinks >= 2.5.3
* debian/copyright: remove mention of files removed upstream
-- Antonio Terceiro <terceiro@debian.org> Fri, 14 Aug 2015 10:54:45 -0300
rails (2:4.2.3-2) experimental; urgency=medium
* Team upload.
* Update dependency of ruby-arel for ruby-activerecord.
* Update dependency of ruby-rack for ruby-actionpack.
* Add new binary package: ruby-activejob.
* Add ruby-byebug and ruby-web-console to recommends for ruby-rails.
-- Pirate Praveen <praveen@debian.org> Fri, 07 Aug 2015 01:38:10 +0530
rails (2:4.2.3-1) experimental; urgency=medium
* Team upload.
* New upstream release; minor update.
-- Pirate Praveen <praveen@debian.org> Tue, 28 Jul 2015 11:21:45 +0530
rails (2:4.1.10-1) unstable; urgency=medium
* New upstream release; bug fixes only
* debian/copyright: fix mention to the license of
guides/assets/javascripts/jquery.min.js
* Drop transitional package ruby-activesupport-2.3; it was only needed for
upgrades from wheezy.
* Drop Breaks:/Replaces: relationships against packages provided by old
versioned source packages (e.g. *-2.3, *-3.2, *-4.0).
-- Antonio Terceiro <terceiro@debian.org> Sun, 24 May 2015 18:11:04 -0300
rails (2:4.1.8-1) unstable; urgency=medium
* New upstream release
- Includes only bug fixes and no behavior changes. In special, includes
fix for [CVE-2014-7818] and [CVE-2014-7829] (Arbitrary file existence
disclosure in Action Pack) (Closes: #770934)
* Add new transitional binary package ruby-activesupport-2.3 plus
appropriate Breaks:/Replaces: fieds in all binary packages to ensure
upgrades from wheezy work (Closes: #768850)
- Many thanks to Andreas Beckmann for helping debug the upgrade issue.
-- Antonio Terceiro <terceiro@debian.org> Tue, 25 Nov 2014 16:51:50 -0200
rails (2:4.1.6-2) unstable; urgency=medium
* fix upgrades from wheezy:
- Remove Breaks: against old packages provided by previous versions of
Rails The Replaces: fields, left untouched, outght to be enough.
- ruby-actionview: Replaces ruby-actionpack-{2.3,3.2} since
ruby-actionview contains files that used to be in ruby-actionpack-*
- ruby-railties: Breaks/Replaces rails (<< 2:4) since ruby-railties
contains /usr/bin/rails which used to be in rails.
* debian/copyright: minor updates
-- Antonio Terceiro <terceiro@debian.org> Tue, 30 Sep 2014 18:33:36 -0300
rails (2:4.1.6-1) unstable; urgency=medium
* New upstream release
* debian/patches/relax-dependencies.patch: dropped, not necessary anymore
-- Antonio Terceiro <terceiro@debian.org> Fri, 26 Sep 2014 15:59:24 -0300
rails (2:4.1.5-1) unstable; urgency=high
* New upstream release
- Fixes CVE-2014-3514: data validation bypass vulnerability
* debian/watch: update to fetch new releases from github.
-- Antonio Terceiro <terceiro@debian.org> Mon, 18 Aug 2014 15:19:04 -0300
rails (2:4.1.4-5) unstable; urgency=medium
* ruby-actionmailer: relax dependency on ruby-mail to work with the 2.6.x
series
-- Antonio Terceiro <terceiro@debian.org> Mon, 04 Aug 2014 14:38:18 -0300
rails (2:4.1.4-4) unstable; urgency=medium
* ruby-rails:
- add Recommends:
- ruby-jquery-rails
- ruby-coffee-rails
- ruby-sqlite3
- ruby-sass-rails
- ruby-uglifier
- ruby-spring
- ruby-turbolinks
- ruby-jbuilder
- ruby-sdoc
- add Breaks/Replaces: rails3
- bump Depends: ruby-sprockets-rails to (>= 2.1.3-1~)
- add Depends: ruby-treetop
- move ruby-activesuppport-3.2 from Breaks: to Conflicts:
- remove Breaks: rails (<< 2:4.1) since we now also provide a
`rails`` binary
* ruby-railties:
- remove Breaks: rails (<< 3:3.2.0)
* ruby-actionmailer:
- drop Depends: ruby-mail (<< 2.6)
cfe https://github.com/rails/rails/commit/bb0890d
* debian/tests/control: fix test dependencies to rails and *not* rails-3.2;
add needs-recommends instead of explicitly listing the recommended
packages
* debian/patches/mona_lisa.jpg_is_PD-Art_and_has_been_removed.patch: removed
as it does not make sense anymore (mona_lisa.jpg is just there).
-- Antonio Terceiro <terceiro@debian.org> Sun, 03 Aug 2014 00:24:26 -0300
rails (2:4.1.4-3) unstable; urgency=medium
* Re-add `rails` binary package
* Improve description for ruby-railties
-- Antonio Terceiro <terceiro@debian.org> Sat, 26 Jul 2014 10:12:46 -0300
rails (2:4.1.4-2) unstable; urgency=medium
[ Antonio Terceiro ]
* Don't install nonsensical binary from activesupport
[ Ondřej Surý ]
* Merge autopkgtests from rails-3.2
* Add missing sources for shCore.js and jquery.min.js
* Upload to unstable since no objections were raised to the RoR Debian
transition plan
* Remove repack script since there's nothing non-free in the upstream
tarball (Closes: #742407)
* Keep the guides/ (CC-BY-SA-3.0) and mona_lisa.jpg (PD), but document
that in d/copyright
-- Ondřej Surý <ondrej@debian.org> Wed, 16 Jul 2014 17:19:07 +0200
rails (2:4.1.4-1) experimental; urgency=medium
[ Antonio Terceiro ]
* debian/rules: adapt dh_clean call
[ Christian Hofstaedtler ]
* Relax dependencies
* Run bundle install --local, as in Debian Rails 3.2
[ Ondřej Surý ]
* New upstream version 4.1.4
* Drop versioning from rails package, we won't to provide just the last
stable upstream major version
* Update dependencies in d/control based on information from gemspec files
* Add ruby-actionview documentation
* Add conflict with old rails package
* Bump epoch to 2: to replace old virtual packages
* Update patches for 4.1.4 release
* Upload to experimental, so we can let the dust settle...
-- Ondřej Surý <ondrej@debian.org> Wed, 16 Jul 2014 15:22:28 +0200
rails-4.0 (4.0.2+dfsg-2) unstable; urgency=low
* Fix dependency -- ruby-rack doesn't have epoch (Closes: #731347)
* Move ruby-activerecord-deprecated-finders from Depends to Recommends
-- Ondřej Surý <ondrej@debian.org> Thu, 12 Dec 2013 13:15:00 +0100
rails-4.0 (4.0.2+dfsg-1) unstable; urgency=low
[ Antonio Terceiro ]
* ruby-actionpack-4.0: tighten versioned dependency on ruby-rack to take
epoch into account.
[ Ondřej Surý ]
* New upstream version 4.0.2+dfsg, fixes:
+ [CVE-2013-6417] Incomplete fix to CVE-2013-0155 (Unsafe Query Generation Risk)
+ [CVE-2013-4491] Reflective XSS Vulnerability in Ruby on Rails
+ [CVE-2013-6415] XSS Vulnerability in number_to_currency
+ [CVE-2013-6414] Denial of Service Vulnerability in Action View
+ [CVE-2013-6416] XSS Vulnerability in simple_format helper
-- Ondřej Surý <ondrej@debian.org> Wed, 04 Dec 2013 10:34:24 +0100
rails-4.0 (4.0.0+dfsg-1) unstable; urgency=low
[ Antonio Terceiro ]
* Migrate to use dh_ruby multi-binary support
[ Ondřej Surý ]
* Initial release of Rails 4.0
* Merge ruby-{active,action}*-X.Y packages into rails-4.0
* Add Copyright headers for syntaxhighlighter
* New upstream version 4.0.0+dfsg
* Update the package based on ftp-master review:
+ Weaken some Conflicts to Breaks (Keeping Conflicts for virtual
packages)
+ Generate actionpack/lib/action_dispatch/journey/parser.rb in the
build using racc
+ Fix copyright to include correct year: (c) 2004-2013 David
Heinemeier Hansson
+ Add MIT or CC-BY license for HTML selector by Assaf Arkin
+ PD-Art license is inconclusive, so we just remove the wikimedia Mona
Lisa picture and patch out the tests that were using it.
(http://commons.wikimedia.org/wiki/Commons:Reuse_of_PD-Art_photographs)
+ Just remove whole guides.rubyonrails.org content from source tarball
(We'll repackage it to ruby-rails-guides-4.0 as soon as we clear the
licensing with upstream.)
+ MIT-LICENSE in templates is needed for templating new projects, add
a lintian-override
* Add dversionmangle to debian/watch
-- Ondřej Surý <ondrej@debian.org> Fri, 19 Jul 2013 15:35:13 +0200
|