[#85349] [Ruby trunk Bug#14334] Segmentation fault after running rspec (ruby/2.5.0/erb.rb:885 / simplecov/source_file.rb:85) — pragtob@...
Issue #14334 has been updated by PragTob (Tobias Pfeiffer).
3 messages
2018/02/02
[#85358] Re: [ruby-cvs:69220] nobu:r62039 (trunk): compile.c: unnecessary freezing — Eric Wong <normalperson@...>
[email protected] wrote:
5 messages
2018/02/03
[#85612] Why require autoconf 2.67+ — leam hall <leamhall@...>
Please pardon the intrusion; I am new to Ruby and like to pull the
6 messages
2018/02/17
[#85616] Re: Why require autoconf 2.67+
— Vít Ondruch <v.ondruch@...>
2018/02/18
VGhpcyBjb3VsZCBoZWxwIHlvdSB0byBidWlsZCBSdWJ5IHdpdGggb2xkZXIgYXV0b2NvbmYgKDIu
[#85634] [Ruby trunk Bug#14494] [PATCH] tool/m4/ruby_replace_type.m4 use AC_CHECK_TYPES for HAVE_* macros — normalperson@...
Issue #14494 has been reported by normalperson (Eric Wong).
3 messages
2018/02/19
[#85674] [Ruby trunk Feature#13618] [PATCH] auto fiber schedule for rb_wait_for_single_fd and rb_waitpid — matz@...
Issue #13618 has been updated by matz (Yukihiro Matsumoto).
5 messages
2018/02/20
[#85686] Re: [Ruby trunk Feature#13618] [PATCH] auto fiber schedule for rb_wait_for_single_fd and rb_waitpid
— Eric Wong <normalperson@...>
2018/02/20
[email protected] wrote:
[#85704] Re: [Ruby trunk Feature#13618] [PATCH] auto fiber schedule for rb_wait_for_single_fd and rb_waitpid
— Koichi Sasada <ko1@...>
2018/02/21
On 2018/02/20 18:06, Eric Wong wrote:
[ruby-core:85598] [Ruby trunk Bug#14481] Backport request for RubyGems 2.7.6
From:
hsbt@...
Date:
2018-02-16 11:01:13 UTC
List:
ruby-core #85598
Issue #14481 has been reported by hsbt (Hiroshi SHIBATA). ---------------------------------------- Bug #14481: Backport request for RubyGems 2.7.6 https://bugs.ruby-lang.org/issues/14481 * Author: hsbt (Hiroshi SHIBATA) * Status: Open * Priority: Normal * Assignee: hsbt (Hiroshi SHIBATA) * Target version: * ruby -v: * Backport: 2.3: REQUIRED, 2.4: REQUIRED, 2.5: REQUIRED ---------------------------------------- RubyGems 2.7.6 has been released. It contained the several vulnerability fixes. http://blog.rubygems.org/2018/02/15/2.7.6-released.html I created patches for all of the active branches of Ruby. ### rubygems-276-for-ruby25.patch This patch for upgrading RubyGems 2.7.3 to 2.7.6 and tiny changes for test-case. So, It includes following fixes: * https://github.com/rubygems/rubygems/pull/2189 * https://github.com/rubygems/rubygems/pull/2194 ### rubygems-276-for-ruby24.patch and rubygems-276-for-ruby23.patch These patches contained RubyGems 2.7.6 security fixes and [tempfile leak fixes](https://github.com/rubygems/rubygems/pull/2194). ### rubygems-276-for-ruby22.patch This patch fixed security vulnerabilities for RubyGems 2.7.6. But I removed patch for "Prevent path traversal when writing to a symlinked basedir outside of the root. Discovered by nmalkin, fixed by Jonathan Claudius and Samuel Giddins." (It was not assigned CVE number) Because to support packaging with symlink was provided after RubyGems 2.5. https://github.com/rubygems/rubygems/pull/1209 So, Ruby 2.2 contained RubyGems 2.4. It's affected by its vulnerability. To nalsh, nagachika, usa Please backport them. ---Files-------------------------------- rubygems-276-for-ruby25.patch (77.4 KB) rubygems-276-for-ruby24.patch (19.5 KB) rubygems-276-for-ruby23.patch (19.5 KB) rubygems-276-for-ruby22.patch (15.5 KB) -- https://bugs.ruby-lang.org/ Unsubscribe: <mailto:[email protected]?subject=unsubscribe> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-core>