soap4r icon indicating copy to clipboard operation
soap4r copied to clipboard

only call untaint on ruby < 2.7

Open kimausloos opened this issue 1 year ago • 1 comments

I saw the issue was fixed in the fork @aogata-inst created, but there was no PR to the original project yet. Since it's a fork and the source is GPL, I don't think I'm doing anything wrong by creating a PR for this. Of course I take no credit, I did not fix the issue.

Original commit message from @aogata-inst:

According to https://bugs.ruby-lang.org/issues/16131, untaint is a no-op on all versions of ruby >= 2.7 and is completely removed on >= ruby 3.2.

Use the pattern established at https://github.com/ruby/reline/pull/61/files to only call this method when it’s relevant.

kimausloos avatar Sep 11 '24 10:09 kimausloos

This closes #26 by the way

kimausloos avatar Sep 11 '24 10:09 kimausloos

@rubyjedi I just found this project and wanted to say THANK YOU for keeping this alive! We're still on the old soap4r gem, but would like to switch to this one. One of the reasons is the deprecation warnings that this PR addresses.

Is there any interest in pulling this change in and releasing a new version?

Oh, and thanks to @kimausloos and @aogata-inst, of course!

tmcabee avatar Oct 10 '24 07:10 tmcabee

I will work through the backlog of PRs over the next weekend or two. Thanks for pinging about it and bringing this back onto my radar.

rubyjedi avatar Oct 10 '24 23:10 rubyjedi

Thanks! Just curious, are you planning to release a new gem version, or waiting for more changes to bump it?

On Sun, Oct 20, 2024 at 3:24 PM Laurence A. Lee @.***> wrote:

Merged #29 https://github.com/rubyjedi/soap4r/pull/29 into master.

— Reply to this email directly, view it on GitHub https://github.com/rubyjedi/soap4r/pull/29#event-14755150412, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAAPMIJ337LL4N7NIURLIMDZ4P7P5AVCNFSM6AAAAABOAWD5SKVHI2DSMVQWIX3LMV45UABCJFZXG5LFIV3GK3TUJZXXI2LGNFRWC5DJN5XDWMJUG42TKMJVGA2DCMQ . You are receiving this because you are subscribed to this thread.Message ID: @.***>

tmcabee avatar Oct 21 '24 10:10 tmcabee

I've got a few more changes planned to refresh the code, and will bump the version shortly after that's done.

rubyjedi avatar Oct 22 '24 22:10 rubyjedi

I've got a few more changes planned to refresh the code, and will bump the version shortly after that's done.

Just wanted to check back and see if you had any plans of bumping the version to go to rubygems? Thanks!

tmcabee avatar Jan 14 '25 20:01 tmcabee

Hey, just wanted to check back and see if you were still planning to publish a new gem version? Thanks!

On Tue, Oct 22, 2024 at 6:49 PM Laurence A. Lee @.***> wrote:

I've got a few more changes planned to refresh the code, and will bump the version shortly after that's done.

— Reply to this email directly, view it on GitHub https://github.com/rubyjedi/soap4r/pull/29#issuecomment-2430457124, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAAPMIJED4WZW2YM4PD3S33Z43I6VAVCNFSM6AAAAABOAWD5SKVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDIMZQGQ2TOMJSGQ . You are receiving this because you are subscribed to this thread.Message ID: @.***>

tmcabee avatar Jan 23 '25 13:01 tmcabee

Hi, yes I intend to publish a new version as time permits. Thanks for the reminder, as this project isn't always at the top of my list -- I'll see if I can get through the changes I had in mind over the next weekend or two.

rubyjedi avatar Jan 23 '25 21:01 rubyjedi

Hi, yes I intend to publish a new version as time permits. Thanks for the reminder, as this project isn't always at the top of my list -- I'll see if I can get through the changes I had in mind over the next weekend or two.

@rubyjedi Just checking back to see if you had made any progress towards a new release? Thanks for any updates!

tmcabee avatar Feb 10 '25 20:02 tmcabee

Hi, yes I intend to publish a new version as time permits. Thanks for the reminder, as this project isn't always at the top of my list -- I'll see if I can get through the changes I had in mind over the next weekend or two.

Hey, I was wondering if you would have a chance to push a new version? Thanks!

tmcabee avatar Mar 26 '25 18:03 tmcabee

Hi, yes I intend to publish a new version as time permits. Thanks for the reminder, as this project isn't always at the top of my list -- I'll see if I can get through the changes I had in mind over the next weekend or two.

Thought I'd check one last time to see if a new version is in the works?

tmcabee avatar May 12 '25 21:05 tmcabee

Any chance you are still planning to release an update?

On Thu, Jan 23, 2025 at 4:31 PM Laurence A. Lee @.***> wrote:

Hi, yes I intend to publish a new version as time permits. Thanks for the reminder, as this project isn't always at the top of my list -- I'll see if I can get through the changes I had in mind over the next weekend or two.

— Reply to this email directly, view it on GitHub https://github.com/rubyjedi/soap4r/pull/29#issuecomment-2611057785, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAAPMIOAV4S6LVVJ6J6R6I32MFNTFAVCNFSM6AAAAABOAWD5SKVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDMMJRGA2TONZYGU . You are receiving this because you are subscribed to this thread.Message ID: @.***>

tmcabee avatar Jun 14 '25 17:06 tmcabee

Hi,

There will probably be a refresh release in the upcoming months (I have been privately asked to do so by several people, and I do apologize for not having as much time to code as I used to). My time is exceptionially constrained this Summer as I'm in the middle a relocation effort and not likely to be fully settled in until early August at best.

In addition to the usual package updates, I'm hoping to find the time to get something like Dependabot and Github Actions operating on this package so patches would be more proactive with less intervention needed on my end to drop a release.

Please do ping me if this request for an update gets stale -- soap4r isn't an actively monitored project on my task list, and could fall off my radar if other tasks draw my attention.

rubyjedi avatar Jun 14 '25 23:06 rubyjedi