From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on dcvr.yhbt.net X-Spam-Level: X-Spam-ASN: AS4713 221.184.0.0/13 X-Spam-Status: No, score=-2.9 required=3.0 tests=AWL,BAYES_00, DKIM_ADSP_CUSTOM_MED,FORGED_GMAIL_RCVD,FREEMAIL_FORGED_FROMDOMAIN, FREEMAIL_FROM,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED,SPF_PASS shortcircuit=no autolearn=no autolearn_force=no version=3.4.2 Received: from neon.ruby-lang.org (neon.ruby-lang.org [221.186.184.75]) by dcvr.yhbt.net (Postfix) with ESMTP id 4219020248 for ; Tue, 12 Mar 2019 21:33:31 +0000 (UTC) Received: from neon.ruby-lang.org (localhost [IPv6:::1]) by neon.ruby-lang.org (Postfix) with ESMTP id C5B3E120BA0; Wed, 13 Mar 2019 06:33:27 +0900 (JST) Received: from o1678948x4.outbound-mail.sendgrid.net (o1678948x4.outbound-mail.sendgrid.net [167.89.48.4]) by neon.ruby-lang.org (Postfix) with ESMTPS id 74D751209DB for ; Wed, 13 Mar 2019 06:33:24 +0900 (JST) Received: by filter0048p3mdw1.sendgrid.net with SMTP id filter0048p3mdw1-11516-5C8825A2-20 2019-03-12 21:33:22.439130115 +0000 UTC m=+80676.659148959 Received: from herokuapp.com (unknown [54.196.67.112]) by ismtpd0049p1mdw1.sendgrid.net (SG) with ESMTP id ZTvxluOmTeOO0fFP5tK23g for ; Tue, 12 Mar 2019 21:33:22.418 +0000 (UTC) Date: Tue, 12 Mar 2019 21:33:22 +0000 (UTC) From: nagachika00@gmail.com Message-ID: References: Mime-Version: 1.0 X-Redmine-MailingListIntegration-Message-Ids: 67244 X-Redmine-Project: ruby-trunk X-Redmine-Issue-Id: 15637 X-Redmine-Issue-Author: hsbt X-Redmine-Sender: nagachika X-Mailer: Redmine X-Redmine-Host: bugs.ruby-lang.org X-Redmine-Site: Ruby Issue Tracking System X-Auto-Response-Suppress: All Auto-Submitted: auto-generated X-SG-EID: =?us-ascii?Q?O2wxg26uOO6cft6GjkEp=2FGevTnH9lR=2FEdG60AX3F8=2FCsFjP18uxOZAUEXCbDuQ?= =?us-ascii?Q?11R17dDCEQOYeMJjhofWDPIbSXWMa3jzX=2FM=2FONo?= =?us-ascii?Q?ZtMuRrhQRt61mtPHC=2F=2FDlkQz=2F9IU8ei9kzuQ5Ve?= =?us-ascii?Q?F1TSzXZ6244kQDq4RA0gmBOw3N+WKeqPWgtFQQy?= =?us-ascii?Q?zd46haAcTyPrZLH8YhVhQrDVgTdPN+MbPGw=3D=3D?= To: ruby-core@ruby-lang.org X-ML-Name: ruby-core X-Mail-Count: 91793 Subject: [ruby-core:91793] [Ruby trunk Bug#15637] Backport RubyGems 3.0.3/2.7.9 X-BeenThere: ruby-core@ruby-lang.org X-Mailman-Version: 2.1.15 Precedence: list Reply-To: Ruby developers List-Id: Ruby developers List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: ruby-core-bounces@ruby-lang.org Sender: "ruby-core" Issue #15637 has been updated by nagachika (Tomoyuki Chikanaga). Backport changed from 2.4: REQUIRED, 2.5: REQUIRED, 2.6: DONE to 2.4: REQUIRED, 2.5: DONE, 2.6: DONE The patch for 2.5.3 was merged at r67234. ---------------------------------------- Bug #15637: Backport RubyGems 3.0.3/2.7.9 https://bugs.ruby-lang.org/issues/15637#change-77067 * Author: hsbt (Hiroshi SHIBATA) * Status: Closed * Priority: Normal * Assignee: * Target version: * ruby -v: * Backport: 2.4: REQUIRED, 2.5: DONE, 2.6: DONE ---------------------------------------- I released RubyGems 3.0.3 and 2.7.9 today. They contain multiple vulnerability fixes. * https://blog.rubygems.org/2019/03/05/3.0.3-released.html * https://blog.rubygems.org/2019/03/05/2.7.9-released.html I attached the patches for Ruby 2.4, 2.5 and 2.6. ---Files-------------------------------- ruby-2.4.5-rubygems.patch (12.4 KB) ruby-2.5.3-rubygems.patch (12.4 KB) ruby-2.6.1-rubygems.patch (17.6 KB) ruby-2.4.5-rubygems-v2.patch (12.5 KB) ruby-2.5.3-rubygems-v2.patch (12.5 KB) ruby-2.6.1-rubygems-v2.patch (17.7 KB) -- https://bugs.ruby-lang.org/