Changelog for
ruby3.1-rubygem-activestorage-5.2-5.2.8.1-lp155.1.5.x86_64.rpm :
* Thu Aug 04 2022 Stephan Kulow
updated to version 5.2.8.1 see installed CHANGELOG.md [#]# Rails 5.2.8.1 (July 12, 2022) ##
* No changes. [#]# Rails 5.2.8 (May 09, 2022) ##
* No changes.
* Thu Apr 28 2022 Stephan Kulow updated to version 5.2.7.1 see installed CHANGELOG.md [#]# Rails 5.2.7.1 (April 26, 2022) ##
* No changes. [#]# Rails 5.2.7 (March 10, 2022) ##
* Fix `ActiveStorage.supported_image_processing_methods` and `ActiveStorage.unsupported_image_processing_arguments` that were not being applied.
* Rafael Mendonça França
* [#]# Rails 5.2.6.3 (March 08, 2022) ##
* Added image transformation validation via configurable allow-list. Variant now offers a configurable allow-list for transformation methods in addition to a configurable deny-list for arguments. [CVE-2022-21831]
* Tue Feb 15 2022 Stephan Kulow updated to version 5.2.6.2 see installed CHANGELOG.md [#]# Rails 5.2.6.2 (February 11, 2022) ##
* No changes. [#]# Rails 5.2.6.1 (February 11, 2022) ##
* No changes.
* Thu Jun 24 2021 Stephan Kulow updated to version 5.2.6 see installed CHANGELOG.md [#]# Rails 5.2.6 (May 05, 2021) ##
* No changes. [#]# Rails 5.2.5 (March 26, 2021) ##
* Marcel is upgraded to version 1.0.0 to avoid a dependency on GPL-licensed mime types data.
* George Claghorn
*
* The Poppler PDF previewer renders a preview image using the original document\'s crop box rather than its media box, hiding print margins. This matches the behavior of the MuPDF previewer.
* Vincent Robert
* [#]# Rails 5.2.4.6 (May 05, 2021) ##
* No changes. [#]# Rails 5.2.4.5 (February 10, 2021) ##
* No changes.
* Fri Sep 25 2020 Stephan Kulow updated to version 5.2.4.4 see installed CHANGELOG.md [#]# Rails 5.2.4.4 (September 09, 2020) ##
* No changes. [#]# Rails 5.2.4.3 (May 18, 2020) ##
* [CVE-2020-8162] Include Content-Length in signature for ActiveStorage direct upload
* Thu May 07 2020 Stephan Kulow - updated to version 5.2.4.2 see installed CHANGELOG.md
* Fri Dec 20 2019 Marcus Rueckert - update to version 5.2.4.1 (CVE-2019-16782): https://weblog.rubyonrails.org/2019/12/18/Rails-5-2-4-1-has-been-released/
* Thu Nov 28 2019 Manuel Schnitzer - updated to version 5.2.4
* no changes
* Fri Mar 29 2019 Stephan Kulow - updated to version 5.2.3 see installed CHANGELOG.md [#]# Rails 5.2.3 (March 27, 2019) ##
* No changes.
* Thu Mar 14 2019 Marcus Rueckert - update to version 5.2.2.1: https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/ CVE-2019-5418 CVE-2019-5419 CVE-2019-5420
* Sat Jan 19 2019 Marcus Rueckert - rb_build_ruby_abi needs to be rb_build_ruby_abis
* Fri Jan 18 2019 Marcus Rueckert - limit to ruby 2.5 and above for 42.3/sle12
* Sat Dec 08 2018 Stephan Kulow - updated to version 5.2.2 see installed CHANGELOG.md [#]# Rails 5.2.2 (December 04, 2018) ##
* Support multiple submit buttons in Active Storage forms.
* Chrıs Seelus
*
* Fix `ArgumentError` when uploading to amazon s3
* Hiroki Sanpei
*
* Add a foreign-key constraint to the `active_storage_attachments` table for blobs.
* George Claghorn
*
* Discard `ActiveStorage::PurgeJobs` for missing blobs.
* George Claghorn
*
* Fix uploading Tempfiles to Azure Storage.
* George Claghorn
*
* Mon Dec 03 2018 mschnitzerAATTsuse.com- updated to version 5.2.1.1 (boo#1118076)- addresses a security vulnerability (CVE-2018-16477, boo#1117641) Signed download URLs generated by `ActiveStorage` for Google Cloud Storage service and Disk service include `content-disposition` and `content-type` parameters that an attacker can modify. This can be used to upload specially crafted HTML files and have them served and executed inline. Combined with other techniques such as cookie bombing and specially crafted AppCache manifests, an attacker can gain access to private signed URLs within a specific storage path. Vulnerable apps are those using either GCS or the Disk service in production. Other storage services such as S3 or Azure aren\'t affected. All users running an affected release should either upgrade or use one of the workarounds immediately. For those using GCS, it\'s also recommended to run the following to update existing blobs: ``` ActiveStorage::Blob.find_each do |blob| blob.send :update_service_metadata end ```
* Wed Aug 08 2018 mschnitzerAATTsuse.com- updated to version 5.2.1 (boo#1104209)
* Fix direct upload with zero-byte files. (George Claghorn)
* Exclude JSON root from `active_storage/direct_uploads#create` response. (Javan Makhmali)
* Mon Apr 16 2018 mschnitzerAATTsuse.com- initialize package see changelog: https://github.com/rails/rails/blob/v5.2.0/activestorage/CHANGELOG.md