SECURITY: Bump Rails to 7.0.3.1 (#17469)

https://discuss.rubyonrails.org/t/81017
This commit is contained in:
David Taylor 2022-07-13 11:17:46 +01:00 committed by GitHub
parent b530781d71
commit ee07f6da7d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
3 changed files with 30 additions and 29 deletions

View File

@ -18,7 +18,7 @@ else
# this allows us to include the bits of rails we use without pieces we do not. # this allows us to include the bits of rails we use without pieces we do not.
# #
# To issue a rails update bump the version number here # To issue a rails update bump the version number here
rails_version = '7.0.3' rails_version = '7.0.3.1'
gem 'actionmailer', rails_version gem 'actionmailer', rails_version
gem 'actionpack', rails_version gem 'actionpack', rails_version
gem 'actionview', rails_version gem 'actionview', rails_version

View File

@ -8,25 +8,25 @@ GIT
GEM GEM
remote: https://rubygems.org/ remote: https://rubygems.org/
specs: specs:
actionmailer (7.0.3) actionmailer (7.0.3.1)
actionpack (= 7.0.3) actionpack (= 7.0.3.1)
actionview (= 7.0.3) actionview (= 7.0.3.1)
activejob (= 7.0.3) activejob (= 7.0.3.1)
activesupport (= 7.0.3) activesupport (= 7.0.3.1)
mail (~> 2.5, >= 2.5.4) mail (~> 2.5, >= 2.5.4)
net-imap net-imap
net-pop net-pop
net-smtp net-smtp
rails-dom-testing (~> 2.0) rails-dom-testing (~> 2.0)
actionpack (7.0.3) actionpack (7.0.3.1)
actionview (= 7.0.3) actionview (= 7.0.3.1)
activesupport (= 7.0.3) activesupport (= 7.0.3.1)
rack (~> 2.0, >= 2.2.0) rack (~> 2.0, >= 2.2.0)
rack-test (>= 0.6.3) rack-test (>= 0.6.3)
rails-dom-testing (~> 2.0) rails-dom-testing (~> 2.0)
rails-html-sanitizer (~> 1.0, >= 1.2.0) rails-html-sanitizer (~> 1.0, >= 1.2.0)
actionview (7.0.3) actionview (7.0.3.1)
activesupport (= 7.0.3) activesupport (= 7.0.3.1)
builder (~> 3.1) builder (~> 3.1)
erubi (~> 1.4) erubi (~> 1.4)
rails-dom-testing (~> 2.0) rails-dom-testing (~> 2.0)
@ -35,15 +35,15 @@ GEM
actionview (>= 6.0.a) actionview (>= 6.0.a)
active_model_serializers (0.8.4) active_model_serializers (0.8.4)
activemodel (>= 3.0) activemodel (>= 3.0)
activejob (7.0.3) activejob (7.0.3.1)
activesupport (= 7.0.3) activesupport (= 7.0.3.1)
globalid (>= 0.3.6) globalid (>= 0.3.6)
activemodel (7.0.3) activemodel (7.0.3.1)
activesupport (= 7.0.3) activesupport (= 7.0.3.1)
activerecord (7.0.3) activerecord (7.0.3.1)
activemodel (= 7.0.3) activemodel (= 7.0.3.1)
activesupport (= 7.0.3) activesupport (= 7.0.3.1)
activesupport (7.0.3) activesupport (7.0.3.1)
concurrent-ruby (~> 1.0, >= 1.0.2) concurrent-ruby (~> 1.0, >= 1.0.2)
i18n (>= 1.6, < 2) i18n (>= 1.6, < 2)
minitest (>= 5.1) minitest (>= 5.1)
@ -349,9 +349,9 @@ GEM
rails_multisite (4.0.1) rails_multisite (4.0.1)
activerecord (> 5.0, < 7.1) activerecord (> 5.0, < 7.1)
railties (> 5.0, < 7.1) railties (> 5.0, < 7.1)
railties (7.0.3) railties (7.0.3.1)
actionpack (= 7.0.3) actionpack (= 7.0.3.1)
activesupport (= 7.0.3) activesupport (= 7.0.3.1)
method_source method_source
rake (>= 12.2) rake (>= 12.2)
thor (~> 1.0) thor (~> 1.0)
@ -510,14 +510,14 @@ PLATFORMS
x86_64-linux x86_64-linux
DEPENDENCIES DEPENDENCIES
actionmailer (= 7.0.3) actionmailer (= 7.0.3.1)
actionpack (= 7.0.3) actionpack (= 7.0.3.1)
actionview (= 7.0.3) actionview (= 7.0.3.1)
actionview_precompiler actionview_precompiler
active_model_serializers (~> 0.8.3) active_model_serializers (~> 0.8.3)
activemodel (= 7.0.3) activemodel (= 7.0.3.1)
activerecord (= 7.0.3) activerecord (= 7.0.3.1)
activesupport (= 7.0.3) activesupport (= 7.0.3.1)
addressable addressable
annotate annotate
aws-sdk-s3 aws-sdk-s3
@ -597,7 +597,7 @@ DEPENDENCIES
rack-protection rack-protection
rails_failover rails_failover
rails_multisite rails_multisite
railties (= 7.0.3) railties (= 7.0.3.1)
rake rake
rb-fsevent rb-fsevent
rbtrace rbtrace

View File

@ -102,6 +102,7 @@ module Discourse
config.action_controller.forgery_protection_origin_check = false config.action_controller.forgery_protection_origin_check = false
config.active_record.belongs_to_required_by_default = false config.active_record.belongs_to_required_by_default = false
config.active_record.legacy_connection_handling = true config.active_record.legacy_connection_handling = true
config.active_record.yaml_column_permitted_classes = [Hash, HashWithIndifferentAccess]
# we skip it cause we configure it in the initializer # we skip it cause we configure it in the initializer
# the railtie for message_bus would insert it in the # the railtie for message_bus would insert it in the