{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":524204103,"defaultBranch":"main","name":"rspec-viewcomponent","ownerLogin":"ViewComponent","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2022-08-12T19:34:08.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/93401166?v=4","public":true,"private":false,"isOrgOwned":true},"refInfo":{"name":"","listCacheKey":"v0:1680618969.0","currentOid":""},"activityList":{"items":[{"before":"878522dc71daf828cb2161886aa785884d55e57a","after":null,"ref":"refs/heads/dependabot/bundler/rails-html-sanitizer-1.5.0","pushedAt":"2023-04-04T14:36:09.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"}},{"before":"cfd238273cd36ea4e646ae0d3e02492486864499","after":"83fafc91b6d861180605e567b1cc0fe1cf309935","ref":"refs/heads/main","pushedAt":"2023-04-04T14:36:00.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"boardfish","name":"Simon Fish","path":"/boardfish","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/20680337?s=80&v=4"},"commit":{"message":"Bump rails-html-sanitizer from 1.4.3 to 1.5.0 (#11)\n\nBumps\r\n[rails-html-sanitizer](https://github.com/rails/rails-html-sanitizer)\r\nfrom 1.4.3 to 1.5.0.\r\n
\r\nRelease notes\r\n

Sourced from rails-html-sanitizer's\r\nreleases.

\r\n
\r\n

1.5.0 / 2023-01-20

\r\n\r\n

1.4.4 / 2022-12-13

\r\n\r\n
\r\n
\r\n
\r\nChangelog\r\n

Sourced from rails-html-sanitizer's\r\nchangelog.

\r\n
\r\n

1.5.0 / 2023-01-20

\r\n\r\n

1.4.4 / 2022-12-13

\r\n\r\n
\r\n
\r\n
\r\nCommits\r\n\r\n
\r\n
\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=rails-html-sanitizer&package-manager=bundler&previous-version=1.4.3&new-version=1.5.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don't\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n
\r\nDependabot commands and options\r\n
\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\nYou can disable automated security fix PRs for this repo from the\r\n[Security Alerts\r\npage](https://github.com/ViewComponent/rspec-viewcomponent/network/alerts).\r\n\r\n
\r\n\r\nSigned-off-by: dependabot[bot] \r\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>","shortMessageHtmlLink":"Bump rails-html-sanitizer from 1.4.3 to 1.5.0 (#11)"}},{"before":"4c3b4cbd319f349c22a9fc7425ee4042aa1b67ef","after":null,"ref":"refs/heads/dependabot/bundler/loofah-2.20.0","pushedAt":"2023-04-04T14:35:58.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"}},{"before":"a7bbe3a526992534e41514a5c1be18b9b2b18280","after":"cfd238273cd36ea4e646ae0d3e02492486864499","ref":"refs/heads/main","pushedAt":"2023-04-04T14:35:50.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"boardfish","name":"Simon Fish","path":"/boardfish","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/20680337?s=80&v=4"},"commit":{"message":"Bump loofah from 2.18.0 to 2.20.0 (#10)\n\nBumps [loofah](https://github.com/flavorjones/loofah) from 2.18.0 to\r\n2.20.0.\r\n
\r\nRelease notes\r\n

Sourced from loofah's\r\nreleases.

\r\n
\r\n

2.20.0 / 2023-04-01

\r\n

Features

\r\n
    \r\n
  • Allow SVG attributes color-profile,\r\ncursor, filter, marker, and\r\nmask. [#246]
  • \r\n
  • Allow SVG elements altGlyph, cursor,\r\nfeImage, pattern, and tref. [#246]
  • \r\n
  • Allow protocols fax and modem. [#255]\r\n(Thanks, @​cjba7!)
  • \r\n
\r\n

2.19.1 / 2022-12-13

\r\n

Security

\r\n
    \r\n
  • Address CVE-2022-23514, inefficient regular expression complexity.\r\nSee GHSA-486f-hjj9-9vhh\r\nfor more information.
  • \r\n
  • Address CVE-2022-23515, improper neutralization of data URIs. See GHSA-228g-948r-83gx\r\nfor more information.
  • \r\n
  • Address CVE-2022-23516, uncontrolled recursion. See GHSA-3x8r-x6xp-q4vm\r\nfor more information.
  • \r\n
\r\n

2.19.0 / 2022-09-14

\r\n

Features

\r\n
    \r\n
  • Allow SVG 1.0 color keyword names in CSS attributes. These colors\r\nare part of the CSS Color Module\r\nLevel 3 recommendation released 2022-01-18. [#243]
  • \r\n
\r\n
\r\n
\r\n
\r\nChangelog\r\n

Sourced from loofah's\r\nchangelog.

\r\n
\r\n

2.20.0 / 2023-04-01

\r\n

Features

\r\n
    \r\n
  • Allow SVG attributes color-profile,\r\ncursor, filter, marker, and\r\nmask. [#246]
  • \r\n
  • Allow SVG elements altGlyph, cursor,\r\nfeImage, pattern, and tref. [#246]
  • \r\n
  • Allow protocols fax and modem. [#255]\r\n(Thanks, @​cjba7!)
  • \r\n
\r\n

2.19.1 / 2022-12-13

\r\n

Security

\r\n
    \r\n
  • Address CVE-2022-23514, inefficient regular expression complexity.\r\nSee GHSA-486f-hjj9-9vhh\r\nfor more information.
  • \r\n
  • Address CVE-2022-23515, improper neutralization of data URIs. See GHSA-228g-948r-83gx\r\nfor more information.
  • \r\n
  • Address CVE-2022-23516, uncontrolled recursion. See GHSA-3x8r-x6xp-q4vm\r\nfor more information.
  • \r\n
\r\n

2.19.0 / 2022-09-14

\r\n

Features

\r\n
    \r\n
  • Allow SVG 1.0 color keyword names in CSS attributes. These colors\r\nare part of the CSS Color Module\r\nLevel 3 recommendation released 2022-01-18. [#243]
  • \r\n
\r\n
\r\n
\r\n
\r\nCommits\r\n\r\n
\r\n
\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=loofah&package-manager=bundler&previous-version=2.18.0&new-version=2.20.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don't\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n
\r\nDependabot commands and options\r\n
\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\nYou can disable automated security fix PRs for this repo from the\r\n[Security Alerts\r\npage](https://github.com/ViewComponent/rspec-viewcomponent/network/alerts).\r\n\r\n
\r\n\r\nSigned-off-by: dependabot[bot] \r\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>","shortMessageHtmlLink":"Bump loofah from 2.18.0 to 2.20.0 (#10)"}},{"before":null,"after":"878522dc71daf828cb2161886aa785884d55e57a","ref":"refs/heads/dependabot/bundler/rails-html-sanitizer-1.5.0","pushedAt":"2023-04-04T13:21:22.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"Bump rails-html-sanitizer from 1.4.3 to 1.5.0\n\nBumps [rails-html-sanitizer](https://github.com/rails/rails-html-sanitizer) from 1.4.3 to 1.5.0.\n- [Release notes](https://github.com/rails/rails-html-sanitizer/releases)\n- [Changelog](https://github.com/rails/rails-html-sanitizer/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/rails/rails-html-sanitizer/compare/v1.4.3...v1.5.0)\n\n---\nupdated-dependencies:\n- dependency-name: rails-html-sanitizer\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"Bump rails-html-sanitizer from 1.4.3 to 1.5.0"}},{"before":null,"after":"4c3b4cbd319f349c22a9fc7425ee4042aa1b67ef","ref":"refs/heads/dependabot/bundler/loofah-2.20.0","pushedAt":"2023-04-04T13:21:19.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"Bump loofah from 2.18.0 to 2.20.0\n\nBumps [loofah](https://github.com/flavorjones/loofah) from 2.18.0 to 2.20.0.\n- [Release notes](https://github.com/flavorjones/loofah/releases)\n- [Changelog](https://github.com/flavorjones/loofah/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/flavorjones/loofah/compare/v2.18.0...v2.20.0)\n\n---\nupdated-dependencies:\n- dependency-name: loofah\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"Bump loofah from 2.18.0 to 2.20.0"}},{"before":"8bc8d3ad4d88f7668e27e9e654cee600d25675c6","after":null,"ref":"refs/heads/dependabot/bundler/rack-2.2.6.4","pushedAt":"2023-04-04T13:20:31.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"}},{"before":"46559046c01bb21de111441be98b5fba2289e6f2","after":"a7bbe3a526992534e41514a5c1be18b9b2b18280","ref":"refs/heads/main","pushedAt":"2023-04-04T13:20:23.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"boardfish","name":"Simon Fish","path":"/boardfish","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/20680337?s=80&v=4"},"commit":{"message":"Bump rack from 2.2.4 to 2.2.6.4 (#9)\n\nBumps [rack](https://github.com/rack/rack) from 2.2.4 to 2.2.6.4.\r\n
\r\nChangelog\r\n

Sourced from rack's\r\nchangelog.

\r\n
\r\n

Changelog

\r\n

All notable changes to this project will be documented in this file.\r\nFor info on how to format all future additions to this file please\r\nreference Keep A\r\nChangelog.

\r\n

Unreleased

\r\n

SPEC Changes

\r\n
    \r\n
  • rack.input is now optional. (#1997, [@​ioquatix])
  • \r\n
\r\n

Changed

\r\n
    \r\n
  • rack.input is now optional, and if missing, will raise\r\nan error. Use this to fail on multipart parsing a request without an\r\ninput body. (#2018, [@​ioquatix])
  • \r\n
  • Introduce module Rack::BadRequest which is included in\r\nmultipart and query parser errors. (#2019, [@​ioquatix])
  • \r\n
  • MIME type for JavaScript files (.js) changed from\r\napplication/javascript to text/javascript (1bd0f15)
  • \r\n
  • Add .mjs MIME type (#2057, [@​axilleas])
  • \r\n
\r\n

[3.0.7] - 2023-03-16

\r\n
    \r\n
  • Make query parameters without = have nil\r\nvalues. (#2059, [@​jeremyevans])
  • \r\n
\r\n

[3.0.6.1] - 2023-03-13

\r\n
    \r\n
  • [CVE-2023-27539] Avoid ReDoS in header parsing
  • \r\n
\r\n

[3.0.6] - 2023-03-13

\r\n
    \r\n
  • Add QueryParser#missing_value for handling missing\r\nvalues + tests. (#2052, [@​ioquatix])
  • \r\n
\r\n

[3.0.5] - 2023-03-13

\r\n
    \r\n
  • Split form/query parsing into two steps. (#2038, @​matthewd)
  • \r\n
\r\n

[3.0.4.2] - 2023-03-02

\r\n
    \r\n
  • [CVE-2023-27530] Introduce multipart_total_part_limit to limit total\r\nparts
  • \r\n
\r\n

[3.0.4.1] - 2023-01-17

\r\n
    \r\n
  • [CVE-2022-44571] Fix ReDoS vulnerability in multipart parser
  • \r\n
  • [CVE-2022-44570] Fix ReDoS in Rack::Utils.get_byte_ranges
  • \r\n
  • [CVE-2022-44572] Forbid control characters in attributes (also\r\nReDoS)
  • \r\n
\r\n

[3.0.4] - 2023-01-17

\r\n
    \r\n
  • Rack::Request#POST should consistently raise errors.\r\nCache errors that occur when invoking Rack::Request#POST so\r\nthey can be raised again later. (#2010, [@​ioquatix])
  • \r\n
  • Fix Rack::Lint error message for\r\nHTTP_CONTENT_TYPE and HTTP_CONTENT_LENGTH. (#2007, @​byroot)
  • \r\n
  • Extend Rack::MethodOverride to handle\r\nQueryParser::ParamsTooDeepError error. (#2006, @​byroot)
  • \r\n
\r\n

[3.0.3] - 2022-12-27

\r\n\r\n
\r\n

... (truncated)

\r\n
\r\n
\r\nCommits\r\n
    \r\n
  • 27addc7\r\nbump version
  • \r\n
  • ee7919e\r\nAvoid ReDoS problem
  • \r\n
  • d6b5b2b\r\nbump version
  • \r\n
  • 9aac375\r\nLimit all multipart parts, not just files
  • \r\n
  • 2606ac5\r\nbumping version
  • \r\n
  • f6d4f52\r\nFix ReDoS in Rack::Utils.get_byte_ranges
  • \r\n
  • 20bc90c\r\nbump version
  • \r\n
  • 3677f17\r\nUpdate changelog
  • \r\n
  • ee25ab9\r\nFix ReDoS vulnerability in multipart parser
  • \r\n
  • 19e49f0\r\nForbid control characters in attributes
  • \r\n
  • Additional commits viewable in compare\r\nview
  • \r\n
\r\n
\r\n
\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=rack&package-manager=bundler&previous-version=2.2.4&new-version=2.2.6.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don't\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n
\r\nDependabot commands and options\r\n
\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\nYou can disable automated security fix PRs for this repo from the\r\n[Security Alerts\r\npage](https://github.com/ViewComponent/rspec-viewcomponent/network/alerts).\r\n\r\n
\r\n\r\nSigned-off-by: dependabot[bot] \r\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>","shortMessageHtmlLink":"Bump rack from 2.2.4 to 2.2.6.4 (#9)"}},{"before":null,"after":"8bc8d3ad4d88f7668e27e9e654cee600d25675c6","ref":"refs/heads/dependabot/bundler/rack-2.2.6.4","pushedAt":"2023-03-28T15:23:01.909Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"Bump rack from 2.2.4 to 2.2.6.4\n\nBumps [rack](https://github.com/rack/rack) from 2.2.4 to 2.2.6.4.\n- [Release notes](https://github.com/rack/rack/releases)\n- [Changelog](https://github.com/rack/rack/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/rack/rack/compare/2.2.4...v2.2.6.4)\n\n---\nupdated-dependencies:\n- dependency-name: rack\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"Bump rack from 2.2.4 to 2.2.6.4"}}],"hasNextPage":false,"hasPreviousPage":false,"activityType":"all","actor":null,"timePeriod":"all","sort":"DESC","perPage":30,"cursor":"djE6ks8AAAADEfMqlwA","startCursor":null,"endCursor":null}},"title":"Activity · ViewComponent/rspec-viewcomponent"}