Bump rubyzip from 1.2.1 to 1.3.0
Created by: dependabot[bot]
Bumps rubyzip from 1.2.1 to 1.3.0.
Release notes
Sourced from rubyzip's releases.
v1.3.0
Security
- Add
validate_entry_sizes
option so that callers can trust an entry's reported size when usingextract
#403
- This option defaults to
false
for backward compatibility in this release, but you are strongly encouraged to set it totrue
. It will default totrue
in rubyzip 2.0.New Feature
- Add
add_stored
method to simplify adding entries without compression #366Tooling / Documentation
- Add more gem metadata links #402
v1.2.4
- Do not rewrite zip files opened with
open_buffer
that have not changed #360Tooling / Documentation
- Update
example_recursive.rb
in README #397- Hold CI at
trusty
for now, automatically pick the latest ruby patch version, use rbx-4 and hold jruby at 9.1 #399v1.2.3
- Allow tilde in zip entry names #391 (fixes regression in 1.2.2 from #376)
- Support frozen string literals in more files #390
- Require
pathname
explicitly #388 (fixes regression in 1.2.2 from #376)Tooling / Documentation:
- CI updates #392, #394
- Add changelog entry that was missing for last release #387
- Comment cleanup #385
Since the GitHub release information for 1.2.2 is missing, I will also include it here:
1.2.2
NB: This release drops support for extracting symlinks, because there was no clear way to support this securely. See https://github-redirect.dependabot.com/rubyzip/rubyzip/pull/376#issue-210954555 for details.
- Fix CVE-2018-1000544 #376 / #371
- Fix NoMethodError: undefined method `glob' #363
- Fix handling of stored files (i.e. files not using compression) with general purpose bit 3 set #358
- Fix
close
on StringIO-backed zip file #353- Add
Zip.force_entry_names_encoding
option #340- Update rubocop, apply auto-fixes, and fix regressions caused by said auto-fixes #332, #355
- Save temporary files to temporary directory (rather than current directory) #325
Tooling / Documentation:
... (truncated)
Changelog
Sourced from rubyzip's changelog.
1.3.0 (2019-09-25)
Security
- Add
validate_entry_sizes
option so that callers can trust an entry's reported size when usingextract
#403
- This option defaults to
false
for backward compatibility in this release, but you are strongly encouraged to set it totrue
. It will default totrue
in rubyzip 2.0.New Feature
- Add
add_stored
method to simplify adding entries without compression #366Tooling / Documentation
- Add more gem metadata links #402
1.2.4 (2019-09-06)
- Do not rewrite zip files opened with
open_buffer
that have not changed #360Tooling / Documentation
- Update
example_recursive.rb
in README #397- Hold CI at
trusty
for now, automatically pick the latest ruby patch version, use rbx-4 and hold jruby at 9.1 #3991.2.3
- Allow tilde in zip entry names #391 (fixes regression in 1.2.2 from #376)
- Support frozen string literals in more files #390
- Require
pathname
explicitly #388 (fixes regression in 1.2.2 from #376)Tooling / Documentation:
- CI updates #392, #394
- Add changelog entry that was missing for last release #387
- Comment cleanup #385
1.2.2
NB: This release drops support for extracting symlinks, because there was no clear way to support this securely. See https://github-redirect.dependabot.com/rubyzip/rubyzip/pull/376#issue-210954555 for details.
... (truncated)
- Fix CVE-2018-1000544 #376 / #371
- Fix NoMethodError: undefined method `glob' #363
- Fix handling of stored files (i.e. files not using compression) with general purpose bit 3 set #358
- Fix
close
on StringIO-backed zip file #353- Add
Zip.force_entry_names_encoding
option #340- Update rubocop, apply auto-fixes, and fix regressions caused by said auto-fixes #332, #355
- Save temporary files to temporary directory (rather than current directory) #325
Commits
-
e79d9ea
Merge pull request #407 from rubyzip/v1-3-0 -
7c65e1e
Bump version to 1.3.0 -
d65fe7b
Merge pull request #403 from rubyzip/check-size -
97cb6ae
Warn when an entry size is invalid -
7849f73
Default validate_entry_sizes to false for 1.3 release -
4167f0c
Validate entry sizes when extracting -
94b7fa2
[ci skip] Update changelog -
93505ca
Check expected entry size in add_stored test -
6619bf3
Merge pull request #366 from hainesr/add-stored -
ecb2776
Zip::File.add_stored() to add uncompressed files. - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot ignore this [patch|minor|major] version
will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.