Skip to content

Bump rack from 2.2.3 to 2.2.6.3 - #56

Open
dependabot[bot] wants to merge 119 commits into
developfrom
dependabot/bundler/rack-2.2.6.3
Open

Bump rack from 2.2.3 to 2.2.6.3#56
dependabot[bot] wants to merge 119 commits into
developfrom
dependabot/bundler/rack-2.2.6.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 8, 2023

Copy link
Copy Markdown

Bumps rack from 2.2.3 to 2.2.6.3.

Changelog

Sourced from rack's changelog.

Changelog

All notable changes to this project will be documented in this file. For info on how to format all future additions to this file please reference Keep A Changelog.

[Unreleased]

SPEC Changes

Changed

  • rack.input is now optional, and if missing, will raise an error. Use this to fail on multipart parsing a request without an input body. (#2018, [@​ioquatix])
  • Introduce module Rack::BadRequest which is included in multipart and query parser errors. (#2019, [@​ioquatix])
  • MIME type for JavaScript files (.js) changed from application/javascript to text/javascript (1bd0f15)

[3.0.4.1] - 2023-01-17

[3.0.4] - 2023-01-17

  • Rack::Request#POST should consistently raise errors. Cache errors that occur when invoking Rack::Request#POST so they can be raised again later. (#2010, [@​ioquatix])
  • Fix Rack::Lint error message for HTTP_CONTENT_TYPE and HTTP_CONTENT_LENGTH. (#2007, @​byroot)
  • Extend Rack::MethodOverride to handle QueryParser::ParamsTooDeepError error. (#2006, @​byroot)

[3.0.3] - 2022-12-27

Fixed

[3.0.2] -2022-12-05

Fixed

  • Utils.build_nested_query URL-encodes nested field names including the square brackets.
  • Allow Rack::Response to pass through streaming bodies. (#1993, [@​ioquatix])

[3.0.1] - 2022-11-18

Fixed

  • MethodOverride does not look for an override if a request does not include form/parseable data.
  • Rack::Lint::Wrapper correctly handles respond_to? with to_ary, each, call and to_path, forwarding to the body. (#1981, [@​ioquatix])

[3.0.0] - 2022-09-06

... (truncated)

Commits
  • d6b5b2b bump version
  • 9aac375 Limit all multipart parts, not just files
  • 2606ac5 bumping version
  • f6d4f52 Fix ReDoS in Rack::Utils.get_byte_ranges
  • 20bc90c bump version
  • 3677f17 Update changelog
  • ee25ab9 Fix ReDoS vulnerability in multipart parser
  • 19e49f0 Forbid control characters in attributes
  • ea39e49 Bump patch version.
  • c0f9de4 Rack::MethodOverride handle QueryParser::ParamsTooDeepError (#2011)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Ethan Liu and others added 30 commits October 8, 2021 08:17
FEATURE ekohe/hbs/atlas#152 - Scope options by depend_column on setupForm.

See merge request ekohe/wulin/wulin_master!221
You can pass a condition to the options query
Example

options_condition: "id > 10" will fetch all the options that id gt 10 on the dropdown
…icateColumns to limit the columns that can be duplicated
Feature ekohe/hbs/atlas#183 - Add 'onAddExtraRowClasses' event

See merge request ekohe/wulin/wulin_master!222
…ommodation_group_popup' into 'develop'

ekohe/hbs/atlas#191 - Fix scoped options visual break

See merge request ekohe/wulin/wulin_master!223
…elop'

ekohe/hbs/atlas#184 - Add the DecimalPercentageFormatter

See merge request ekohe/wulin/wulin_master!225
ekohe/hbs/atlas#184 - Allow realtion options on create, edit form and in-grid edit

See merge request ekohe/wulin/wulin_master!224
…eload the master grid when update/create record
…he date selector pop up collapse after the date is selected
https://gitlab.ekohe.com/ekohe/wulin/wulin_master/-/issues/248 make the date selector pop up collapse after the date is selected

See merge request ekohe/wulin/wulin_master!228
ekohe/hbs/atlas#203 - Add addExtraCellClasses event - Mod addExtraRowClasses args

See merge request ekohe/wulin/wulin_master!231
BUG #251 - Avoid create modal popup on view button

See merge request ekohe/wulin/wulin_master!233
Rails 7 - ActionView::Template::Error for toolbar partial

See merge request ekohe/wulin/wulin_master!232
…_form' into 'develop'

BUG https://gitlab.ekohe.com/ekohe/hbs/bss/-/issues/304 Fix_unit_scale_unit_dependency_in_services_edit_form

See merge request ekohe/wulin/wulin_master!234
meltsao and others added 27 commits August 17, 2022 07:38
Feature #245 - delete state if the values are empty

See merge request ekohe/wulin/wulin_master!220
…ug' into 'develop'

BUG - ekohe/hbs/cruise#215 fix multiple multiple_grid_states dropdowns on single screen

See merge request ekohe/wulin/wulin_master!263
FEATURE - ekohe/hbs/atlas#326 Add slick Event onDeletedByAjax callback

See merge request ekohe/wulin/wulin_master!265
BUG - #269 overwrite column editable true if user only has read permission

See merge request ekohe/wulin/wulin_master!267
BUG - #270 change #set as initial post request data in the body instead of url

See merge request ekohe/wulin/wulin_master!270
…evelop'

BUG - #270 grid_state_set_as_initial

See merge request ekohe/wulin/wulin_master!271
…nto 'develop'

Feature #244 - support column coloring behavior version

See merge request ekohe/wulin/wulin_master!269
Feature wulin_master#244 - Add other colors

See merge request ekohe/wulin/wulin_master!272
BUG - #266 materialize tooltips position on screen resize

See merge request ekohe/wulin/wulin_master!266
…_callback' into 'develop'

FEATURE - ekohe/hbs/cruise#244 Add double_click_before_column_edit slick event

See merge request ekohe/wulin/wulin_master!274
https://gitlab.ekohe.com/ekohe/hbs/atlas/-/issues/350 - respond the errors message from the record if we have

See merge request ekohe/wulin/wulin_master!275
Bumps [rack](https://github.com/rack/rack) from 2.2.3 to 2.2.6.3.
- [Release notes](https://github.com/rack/rack/releases)
- [Changelog](https://github.com/rack/rack/blob/main/CHANGELOG.md)
- [Commits](rack/rack@2.2.3...v2.2.6.3)

---
updated-dependencies:
- dependency-name: rack
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Mar 8, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants