--- - branch: MAIN date: Thu Feb 11 14:23:42 UTC 2021 files: - new: '1.6' old: '1.5' path: pkgsrc/databases/ruby-activerecord52/distinfo pathrev: pkgsrc/databases/ruby-activerecord52/distinfo@1.6 type: modified - new: '1.6' old: '1.5' path: pkgsrc/devel/ruby-activejob52/distinfo pathrev: pkgsrc/devel/ruby-activejob52/distinfo@1.6 type: modified - new: '1.6' old: '1.5' path: pkgsrc/devel/ruby-activemodel52/distinfo pathrev: pkgsrc/devel/ruby-activemodel52/distinfo@1.6 type: modified - new: '1.6' old: '1.5' path: pkgsrc/devel/ruby-activestorage52/distinfo pathrev: pkgsrc/devel/ruby-activestorage52/distinfo@1.6 type: modified - new: '1.6' old: '1.5' path: pkgsrc/devel/ruby-activesupport52/distinfo pathrev: pkgsrc/devel/ruby-activesupport52/distinfo@1.6 type: modified - new: '1.6' old: '1.5' path: pkgsrc/devel/ruby-railties52/distinfo pathrev: pkgsrc/devel/ruby-railties52/distinfo@1.6 type: modified - new: '1.92' old: '1.91' path: pkgsrc/lang/ruby/rails.mk pathrev: pkgsrc/lang/ruby/rails.mk@1.92 type: modified - new: '1.6' old: '1.5' path: pkgsrc/mail/ruby-actionmailer52/distinfo pathrev: pkgsrc/mail/ruby-actionmailer52/distinfo@1.6 type: modified - new: '1.6' old: '1.5' path: pkgsrc/www/ruby-actioncable52/distinfo pathrev: pkgsrc/www/ruby-actioncable52/distinfo@1.6 type: modified - new: '1.6' old: '1.5' path: pkgsrc/www/ruby-actionpack52/distinfo pathrev: pkgsrc/www/ruby-actionpack52/distinfo@1.6 type: modified - new: '1.6' old: '1.5' path: pkgsrc/www/ruby-actionview52/distinfo pathrev: pkgsrc/www/ruby-actionview52/distinfo@1.6 type: modified - new: '1.6' old: '1.5' path: pkgsrc/www/ruby-rails52/distinfo pathrev: pkgsrc/www/ruby-rails52/distinfo@1.6 type: modified id: 20210211T142342Z.cd9b7b5b7ac932141d0363780aae8e0154e64455 log: | www/rails52: update to 5.2.4.5 ## Rails 5.2.4.5 (February 10, 2021) ## * Fix possible DoS vector in PostgreSQL money type Carefully crafted input can cause a DoS via the regular expressions used for validating the money format in the PostgreSQL adapter. This patch fixes the regexp. Thanks to @dee-see from Hackerone for this patch! [CVE-2021-22880] *Aaron Patterson* module: pkgsrc subject: 'CVS commit: pkgsrc' unixtime: '1613053422' user: taca