Sourced from rack's releases.
v2.2.7
What's Changed
- Correct the year number in the changelog by
@kimulabin rack/rack#2015- Support underscore in host names for Rack 2.2 (Fixes #2070) by
@jeremyevansin rack/rack#2071New Contributors
@kimulabmade their first contribution in rack/rack#2015Full Changelog: https://github.com/rack/rack/compare/v2.2.6.4...v2.2.7
v2.2.6.4
No release notes provided.
Sourced from rack's changelog.
Changelog
All notable changes to this project will be documented in this file. For info on how to format all future additions to this file please reference Keep A Changelog.
Unreleased
SPEC Changes
rack.inputis now optional. (#1997, [@ioquatix])Changed
rack.inputis now optional, and if missing, will raise an error. Use this to fail on multipart parsing a request without an input body. (#2018, [@ioquatix])- Introduce
module Rack::BadRequestwhich is included in multipart and query parser errors. (#2019, [@ioquatix])- MIME type for JavaScript files (
.js) changed fromapplication/javascripttotext/javascript(1bd0f15)- Add
.mjsMIME type (#2057, [@axilleas])- Update MIME types associated to
.ttf,.woff,.woff2and.otfextensions to use mondernfont/*types. (#2065, [@davidstosik])[3.0.8] - 2023-06-14
- Fix some unused variable verbose warnings. (#2084, [
@jeremyevans],@skipkayhil)[3.0.7] - 2023-03-16
- Make query parameters without
=havenilvalues. (#2059, [@jeremyevans])[3.0.6.1] - 2023-03-13
- [CVE-2023-27539] Avoid ReDoS in header parsing
[3.0.6] - 2023-03-13
- Add
QueryParser#missing_valuefor handling missing values + tests. (#2052, [@ioquatix])[3.0.5] - 2023-03-13
- Split form/query parsing into two steps. (#2038,
@matthewd)[3.0.4.2] - 2023-03-02
- [CVE-2023-27530] Introduce multipart_total_part_limit to limit total parts
[3.0.4.1] - 2023-01-17
- [CVE-2022-44571] Fix ReDoS vulnerability in multipart parser
- [CVE-2022-44570] Fix ReDoS in Rack::Utils.get_byte_ranges
- [CVE-2022-44572] Forbid control characters in attributes (also ReDoS)
[3.0.4] - 2023-01-17
... (truncated)
983b6e3
Bump patch version.e5a30bf
Support underscore in host names for Rack 2.2 (Fixes #2070) (#2071)70185aa
Merge branch '2-2-sec' into 2-2-stable27addc7
bump versionee7919e
Avoid ReDoS problem6f79642
Merge branch '2-2-sec' into 2-2-stabled6b5b2b
bump version9aac375
Limit all multipart parts, not just filescd4c9f0
Correct the year in the changelog (#2015)2606ac5
bumping version