head 1.5; access; symbols pkgsrc-2026Q2:1.4.0.2 pkgsrc-2026Q2-base:1.4 pkgsrc-2026Q1:1.3.0.4 pkgsrc-2026Q1-base:1.3 pkgsrc-2025Q4:1.3.0.2 pkgsrc-2025Q4-base:1.3 pkgsrc-2025Q3:1.2.0.2 pkgsrc-2025Q3-base:1.2 pkgsrc-2025Q2:1.1.0.6 pkgsrc-2025Q2-base:1.1 pkgsrc-2025Q1:1.1.0.4 pkgsrc-2025Q1-base:1.1 pkgsrc-2024Q4:1.1.0.2 pkgsrc-2024Q4-base:1.1; locks; strict; comment @# @; 1.5 date 2026.07.30.15.20.14; author taca; state Exp; branches; next 1.4; commitid dcBLZI1K4WemSGPG; 1.4 date 2026.03.29.14.07.38; author taca; state Exp; branches 1.4.2.1; next 1.3; commitid 7MD3YzIuBQozqSzG; 1.3 date 2025.11.03.08.39.27; author taca; state Exp; branches 1.3.4.1; next 1.2; commitid eEWacFDHLarZi5hG; 1.2 date 2025.08.14.15.22.46; author taca; state Exp; branches; next 1.1; commitid EsnJg8uLp28F8I6G; 1.1 date 2024.12.13.16.47.43; author taca; state Exp; branches; next ; commitid GtE2qOsOTPubsmBF; 1.4.2.1 date 2026.08.05.15.02.21; author maya; state Exp; branches; next ; commitid y80gCkx7EfojAsQG; 1.3.4.1 date 2026.03.31.13.31.42; author maya; state Exp; branches; next ; commitid iqK8mCnuD32ja8AG; desc @@ 1.5 log @www/ruby-rails72: update to 7.2.3.2 Ruby on Rails 7.2.3.2 (2026-07-29) Active Storage * A possible arbitrary file read and remote code execution in Active Storage variant processing (CVE-2026-66066) @ text @$NetBSD: distinfo,v 1.4 2026/03/29 14:07:38 taca Exp $ BLAKE2s (actionview-7.2.3.2.gem) = 8032a1131f3e40091e1ccb0037457d41ac2d01781e920f6c9c40438a25856ac9 SHA512 (actionview-7.2.3.2.gem) = c35345a31731dbea4b60914f9096dbcb296f8324c31fadde8b9f143a3e01fd290a5965883e0f69d92cba992c5e54b6d0507ff8a36fc14bfb7b473f37239a4be9 Size (actionview-7.2.3.2.gem) = 188416 bytes @ 1.4 log @www/ruby-rails72: update to 7.2.3.1 Ruby on Rails 7.2.3.1 (2026-03-23) Active Support * Reject scientific notation in NumberConverter [CVE-2026-33176] Jean Boussier * Fix SafeBuffer#% to preserve unsafe status [CVE-2026-33170] Jean Boussier * Improve performance of NumberToDelimitedConverter [CVE-2026-33169] Jean Boussier Action View * Skip blank attribute names in tag helpers to avoid generating invalid HTML. [CVE-2026-33168] Mike Dalessio Active Storage * Filter user supplied metadata in DirectUploadController [CVE-2026-33173] Jean Boussier * Configurable maxmimum streaming chunk size Makes sure that byte ranges for blobs don't exceed 100mb by default. Content ranges that are too big can result in denial of service. [CVE-2026-33174] Gannon McGibbon * Limit range requests to a single range [CVE-2026-33658] Jean Boussier * Prevent path traversal in DiskService. DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".", ".."), or if the resolved path is outside the storage root directory. #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for example containing null bytes or having an incompatible encoding. Previously, the exception raised may have been ArgumentError or Encoding::CompatibilityError. DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes. [CVE-2026-33195] Mike Dalessio * Prevent glob injection in DiskService#delete_prefixed. Escape glob metacharacters in the resolved path before passing to Dir.glob. Note that this change breaks any existing code that is relying on delete_prefixed to expand glob metacharacters. This change presumes that is unintended behavior (as other storage services do not respect these metacharacters). [CVE-2026-33202] Mike Dalessio Active Model Active Record Action Pack Active Job Action Mailer Action Cable Action Mailbox Action Text Railties * No change except version. @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.3 2025/11/03 08:39:27 taca Exp $ d3 3 a5 3 BLAKE2s (actionview-7.2.3.1.gem) = f74df58276a862ba33e4034c058a196047f2bfbc4411aab755a32cb491c13579 SHA512 (actionview-7.2.3.1.gem) = d3a4e84f987cc962e37ec8030e2a0dc0a126e4facfb4e741242ba599375514ba80fc3e847b102e58bfddc1bd7f2be9848644bf3fb57c8e3267da6e0f04287737 Size (actionview-7.2.3.1.gem) = 188416 bytes @ 1.4.2.1 log @Pullup ticket #7214 - requested by taca www/ruby-rails72: Security fix Revisions pulled up: - databases/ruby-activerecord72/distinfo 1.5 - devel/ruby-activejob72/distinfo 1.5 - devel/ruby-activemodel72/distinfo 1.5 - devel/ruby-activestorage72/PLIST 1.2 - devel/ruby-activestorage72/distinfo 1.5 - devel/ruby-activesupport72/distinfo 1.5 - devel/ruby-railties72/distinfo 1.5 - lang/ruby/rails.mk 1.191 - mail/ruby-actionmailbox72/distinfo 1.5 - mail/ruby-actionmailer72/distinfo 1.5 - textproc/ruby-actiontext72/distinfo 1.5 - www/ruby-actioncable72/distinfo 1.5 - www/ruby-actionpack72/distinfo 1.5 - www/ruby-actionview72/distinfo 1.5 - www/ruby-rails72/distinfo 1.5 --- Module Name: pkgsrc Committed By: taca Date: Thu Jul 30 15:20:15 UTC 2026 Modified Files: pkgsrc/databases/ruby-activerecord72: distinfo pkgsrc/devel/ruby-activejob72: distinfo pkgsrc/devel/ruby-activemodel72: distinfo pkgsrc/devel/ruby-activestorage72: PLIST distinfo pkgsrc/devel/ruby-activesupport72: distinfo pkgsrc/devel/ruby-railties72: distinfo pkgsrc/lang/ruby: rails.mk pkgsrc/mail/ruby-actionmailbox72: distinfo pkgsrc/mail/ruby-actionmailer72: distinfo pkgsrc/textproc/ruby-actiontext72: distinfo pkgsrc/www/ruby-actioncable72: distinfo pkgsrc/www/ruby-actionpack72: distinfo pkgsrc/www/ruby-actionview72: distinfo pkgsrc/www/ruby-rails72: distinfo Log Message: www/ruby-rails72: update to 7.2.3.2 Ruby on Rails 7.2.3.2 (2026-07-29) Active Storage * A possible arbitrary file read and remote code execution in Active Storage variant processing (CVE-2026-66066) @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (actionview-7.2.3.2.gem) = 8032a1131f3e40091e1ccb0037457d41ac2d01781e920f6c9c40438a25856ac9 SHA512 (actionview-7.2.3.2.gem) = c35345a31731dbea4b60914f9096dbcb296f8324c31fadde8b9f143a3e01fd290a5965883e0f69d92cba992c5e54b6d0507ff8a36fc14bfb7b473f37239a4be9 Size (actionview-7.2.3.2.gem) = 188416 bytes @ 1.3 log @www/ruby-actionview72: update to 7.2.3 7.2.3 (2025-10-28) * Fix javascript_include_tag type option to accept either strings and symbols. javascript_include_tag "application", type: :module javascript_include_tag "application", type: "module" Previously, only the string value was recoginized. Jean Boussier * Fix excerpt helper with non-whitespace separator. Jonathan Hefner * Respect html_options[:form] when collection_checkboxes generates the hidden . Riccardo Odone * Layouts have access to local variables passed to render. This fixes #31680 which was a regression in Rails 5.1. Mike Dalessio * Argument errors related to strict locals in templates now raise an ActionView::StrictLocalsError, and all other argument errors are reraised as-is. Previously, any ArgumentError raised during template rendering was swallowed during strict local error handling, so that an ArgumentError unrelated to strict locals (e.g., a helper method invoked with incorrect arguments) would be replaced by a similar ArgumentError with an unrelated backtrace, making it difficult to debug templates. Now, any ArgumentError unrelated to strict locals is reraised, preserving the original backtrace for developers. Also note that ActionView::StrictLocalsError is a subclass of ArgumentError, so any existing code that rescues ArgumentError will continue to work. Fixes #52227. Mike Dalessio * Fix stack overflow error in dependency tracker when dealing with circular dependencies Jean Boussier * Fix a crash in ERB template error highlighting when the error occurs on a line in the compiled template that is past the end of the source template. Martin Emde * Improve reliability of ERB template error highlighting. Fix infinite loops and crashes in highlighting and improve tolerance for alternate ERB handlers. Martin Emde @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.2 2025/08/14 15:22:46 taca Exp $ d3 3 a5 3 BLAKE2s (actionview-7.2.3.gem) = 114aeb7b117a91eeac923c816d9f1a2a45faf05df8d3965ab00fc6e81f036db4 SHA512 (actionview-7.2.3.gem) = a71e801f5bf0a0b9f81c6328982147ef2567da19cdae9a275a0b022c39cb989fffc4435d5664facbc030e5da7b68ac3746ecff45ba3e7e27abc21691d3175f65 Size (actionview-7.2.3.gem) = 188416 bytes @ 1.3.4.1 log @Pullup ticket #7061 - requested by taca databases/ruby-activerecord72: Security fix devel/ruby-activejob72: Security fix devel/ruby-activemodel72: Security fix devel/ruby-activestorage72: Security fix devel/ruby-activesupport72: Security fix devel/ruby-activesupport72: Security fix devel/ruby-railties72: Security fix devel/ruby-railties72: Security fix lang/ruby: Security fix mail/ruby-actionmailbox72: Security fix mail/ruby-actionmailer72: Security fix textproc/ruby-actiontext72: Security fix www/ruby-actioncable72: Security fix www/ruby-actionpack72: Security fix www/ruby-actionpack72: Security fix www/ruby-actionview72: Security fix www/ruby-rails72: Security fix Revisions pulled up: - databases/ruby-activerecord72/distinfo 1.4 - devel/ruby-activejob72/distinfo 1.4 - devel/ruby-activemodel72/distinfo 1.4 - devel/ruby-activestorage72/distinfo 1.4 - devel/ruby-activesupport72/Makefile 1.4 - devel/ruby-activesupport72/distinfo 1.4 - devel/ruby-railties72/Makefile 1.5 - devel/ruby-railties72/distinfo 1.4 - lang/ruby/rails.mk 1.188 - mail/ruby-actionmailbox72/distinfo 1.4 - mail/ruby-actionmailer72/distinfo 1.4 - textproc/ruby-actiontext72/distinfo 1.4 - www/ruby-actioncable72/distinfo 1.4 - www/ruby-actionpack72/Makefile 1.3 - www/ruby-actionpack72/distinfo 1.4 - www/ruby-actionview72/distinfo 1.4 - www/ruby-rails72/distinfo 1.4 --- Module Name: pkgsrc Committed By: taca Date: Sun Mar 29 14:07:39 UTC 2026 Modified Files: pkgsrc/databases/ruby-activerecord72: distinfo pkgsrc/devel/ruby-activejob72: distinfo pkgsrc/devel/ruby-activemodel72: distinfo pkgsrc/devel/ruby-activestorage72: distinfo pkgsrc/devel/ruby-activesupport72: Makefile distinfo pkgsrc/devel/ruby-railties72: Makefile distinfo pkgsrc/mail/ruby-actionmailbox72: distinfo pkgsrc/mail/ruby-actionmailer72: distinfo pkgsrc/textproc/ruby-actiontext72: distinfo pkgsrc/www/ruby-actioncable72: distinfo pkgsrc/www/ruby-actionpack72: Makefile distinfo pkgsrc/www/ruby-actionview72: distinfo pkgsrc/www/ruby-rails72: distinfo Log Message: www/ruby-rails72: update to 7.2.3.1 Ruby on Rails 7.2.3.1 (2026-03-23) Active Support * Reject scientific notation in NumberConverter [CVE-2026-33176] Jean Boussier * Fix SafeBuffer#% to preserve unsafe status [CVE-2026-33170] Jean Boussier * Improve performance of NumberToDelimitedConverter [CVE-2026-33169] Jean Boussier Action View * Skip blank attribute names in tag helpers to avoid generating invalid HTML. [CVE-2026-33168] Mike Dalessio Active Storage * Filter user supplied metadata in DirectUploadController [CVE-2026-33173] Jean Boussier * Configurable maxmimum streaming chunk size Makes sure that byte ranges for blobs don't exceed 100mb by default. Content ranges that are too big can result in denial of service. [CVE-2026-33174] Gannon McGibbon * Limit range requests to a single range [CVE-2026-33658] Jean Boussier * Prevent path traversal in DiskService. DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".", ".."), or if the resolved path is outside the storage root directory. #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for example containing null bytes or having an incompatible encoding. Previously, the exception raised may have been ArgumentError or Encoding::CompatibilityError. DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes. [CVE-2026-33195] Mike Dalessio * Prevent glob injection in DiskService#delete_prefixed. Escape glob metacharacters in the resolved path before passing to Dir.glob. Note that this change breaks any existing code that is relying on delete_prefixed to expand glob metacharacters. This change presumes that is unintended behavior (as other storage services do not respect these metacharacters). [CVE-2026-33202] Mike Dalessio Active Model Active Record Action Pack Active Job Action Mailer Action Cable Action Mailbox Action Text Railties * No change except version. --- Module Name: pkgsrc Committed By: taca Date: Sun Mar 29 14:26:36 UTC 2026 Modified Files: pkgsrc/lang/ruby: rails.mk Log Message: lang/ruby: update to rails to 7.2.3.1 Make sure to update rails72 to 7.2.3.1. @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (actionview-7.2.3.1.gem) = f74df58276a862ba33e4034c058a196047f2bfbc4411aab755a32cb491c13579 SHA512 (actionview-7.2.3.1.gem) = d3a4e84f987cc962e37ec8030e2a0dc0a126e4facfb4e741242ba599375514ba80fc3e847b102e58bfddc1bd7f2be9848644bf3fb57c8e3267da6e0f04287737 Size (actionview-7.2.3.1.gem) = 188416 bytes @ 1.2 log @www/ruby-rails72: update to 7.2.2.2 Ruby on Rails 7.2.2.2 (2025-08-13) Active Record * Call inspect on ids in RecordNotFound error [CVE-2025-55193] Gannon McGibbon, John Hawthorn Active Storage * Remove dangerous transformations [CVE-2025-24293] Zack Deveau @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.1 2024/12/13 16:47:43 taca Exp $ d3 3 a5 3 BLAKE2s (actionview-7.2.2.2.gem) = c1938edf1cd5ad19d0947b5ebcc49165f82dd081c807c91a4cab801b0a227a7c SHA512 (actionview-7.2.2.2.gem) = 0a7117375e514d0d8bd70f40a7350d6b9b8f52b34e1c6cd5acd7d4ef3e77b9a3aa9b38f4b0cd657e6194071fcb42a2f98de535afe30fca26f2363815f7dde4ed Size (actionview-7.2.2.2.gem) = 186880 bytes @ 1.1 log @www/ruby-actionview72: add package version 7.2.2.1 Action View Action View is a framework for handling view template lookup and rendering, and provides view helpers that assist when building HTML forms, Atom feeds and more. Template formats that Action View handles are ERB (embedded Ruby, typically used to inline short Ruby snippets inside HTML), and XML Builder. @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (actionview-7.2.2.1.gem) = 0eeac887e10f496f1f02f53989c5732664177b1a3ce096f1aaa7a88bff180ac7 SHA512 (actionview-7.2.2.1.gem) = c4fde66acf47be497b2f1c6deb567aad081e52d45ca587083390be5ab11da7ad4e31283aabf8bb5b2dc2b424720148c0b12cf1981fa413d2e0ac8a720bfaca1e Size (actionview-7.2.2.1.gem) = 186880 bytes @