Bump rails from 5.2.3 to 6.0.3.2
Bumps rails from 5.2.3 to 6.0.3.2.
Release notes
Sourced from rails's releases.
6.0.3.1
Active Support
[CVE-2020-8165] Deprecate Marshal.load on raw cache read in RedisCacheStore
[CVE-2020-8165] Avoid Marshal.load on raw cache value in MemCacheStore
Active Model
- No changes.
Active Record
- No changes.
Action View
- [CVE-2020-8167] Check that request is same-origin prior to including CSRF token in XHRs
Action Pack
[CVE-2020-8166] HMAC raw CSRF token before masking it, so it cannot be used to reconstruct a per-form token
[CVE-2020-8164] Return self when calling #each, #each_pair, and #each_value instead of the raw @parameters hash
Active Job
- No changes.
Action Mailer
- No changes.
Action Cable
- No changes.
Active Storage
... (truncated)
Commits
fbe2433Preparing for 6.0.3.2 release11052e0Update changelog2121b9dOnly allow ActionableErrors if show_detailed_exceptions is enabled34991a6Preparing for 6.0.3.1 release2c8fe2abumping version, updating changelog0ad524aupdate changelog47a8dc3Check that request is same-origin prior to including CSRF token in XHRs29aa538HMAC raw CSRF token before masking it, so it cannot be used to reconstruct a ...bd39a13activesupport: Deprecate Marshal.load on raw cache read in RedisCacheStore0a7ce52activesupport: Avoid Marshal.load on raw cache value in MemCacheStore- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language -
@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot dashboard:
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)
Dependabot tried to add @ervalhous as a reviewer to this PR, but received the following error from GitHub:
POST https://api.github.com/repos/autoforce/APIcasso/pulls/138/requested_reviewers: 422 - Reviews may only be requested from collaborators. One or more of the users or teams you specified is not a collaborator of the autoforce/APIcasso repository. // See: https://developer.github.com/v3/pulls/review_requests/#create-a-review-request
Codecov Report
Merging #138 into master will decrease coverage by
85.59%. The diff coverage isn/a.
@@ Coverage Diff @@
## master #138 +/- ##
===========================================
- Coverage 96.99% 11.40% -85.60%
===========================================
Files 24 15 -9
Lines 931 614 -317
===========================================
- Hits 903 70 -833
- Misses 28 544 +516
| Impacted Files | Coverage Δ | |
|---|---|---|
| spec/requests/singularized/requests_spec.rb | 1.87% <0.00%> (-97.50%) |
:arrow_down: |
| ...equests/plurarized/requests_with_plurarize_spec.rb | 1.87% <0.00%> (-97.50%) |
:arrow_down: |
| spec/token/token_spec.rb | 4.23% <0.00%> (-95.77%) |
:arrow_down: |
| spec/requests/batch_spec.rb | 6.12% <0.00%> (-93.88%) |
:arrow_down: |
| spec/requests/singularized/bad_requests_spec.rb | 12.50% <0.00%> (-87.50%) |
:arrow_down: |
| ...sts/plurarized/bad_requests_with_plurarize_spec.rb | 12.50% <0.00%> (-87.50%) |
:arrow_down: |
| spec/models/used_model_spec.rb | 41.17% <0.00%> (-58.83%) |
:arrow_down: |
| app/models/apicasso/key.rb | 63.63% <0.00%> (-36.37%) |
:arrow_down: |
| spec/apicasso_spec.rb | 66.66% <0.00%> (-33.34%) |
:arrow_down: |
| spec/dummy/app/models/used_model.rb | 46.15% <0.00%> (-15.39%) |
:arrow_down: |
| ... and 9 more |
Continue to review full report at Codecov.
Legend - Click here to learn more
Δ = absolute <relative> (impact),ø = not affected,? = missing dataPowered by Codecov. Last update a95b5fc...959aed2. Read the comment docs.