Commit Graph

5 Commits

Author SHA1 Message Date
Jarek Prokop 9ad85ebe74 Work around infra's networking.
TestBundledCA is commented out since some of the build
infra can see DNS but then cannot connect.
Ideally not even DNS can be resolved for the rubygems.org.
The tests always get omitted in builds
as long as the infra does not allow connecting outside,
which is what we expect as correct behavior from mock.

Related: RHEL-36189
2024-05-13 22:17:13 +02:00
Jun Aruga 9ad4115fe3 Upgrade to Ruby 3.0.7.
* Upgrade to Ruby 3.0.7.
  Resolves: RHEL-36189

The released Ruby 3.0.5 includes the following fix.

* Fix HTTP response splitting in CGI.
  Resolves: RHEL-36193

The released Ruby 3.0.6 includes the following fixes.

* Fix ReDoS vulnerability in URI.
  Resolves: RHEL-36196
* Fix ReDoS vulnerability in Time.
  Resolves: RHEL-36205

The released Ruby 3.0.7 includes the following fixes.

* Fix buffer overread vulnerability in StringIO.
  Resolves: RHEL-36198
* Fix RCE vulnerability with .rdoc_options in RDoc.
  Resolves: RHEL-36200
* Fix arbitrary memory address read vulnerability with Regex search.
  Resolves: RHEL-36203

Added the following patch.
* Fix net-http test errors due to expired certificate.
  The patch ruby-3.4.0-ruby-net-http-Renew-test-certificates.patch was copied
  from the part on the Fedora rawhide
  <05a6c9c8f3>.
2024-05-13 22:16:53 +02:00
Adam Samalik 46666c437d re-import sources as agreed with the maintainer 2023-07-11 11:47:49 +02:00
James Antill c1f99e5472 Import rpm: 6841a2fe4f7da03f9b322844763f4ef60d27dcb5 2023-02-23 23:51:39 -05:00
James Antill 26e6c30079 Import rpm: 6841a2fe4f7da03f9b322844763f4ef60d27dcb5 2023-02-20 02:14:24 -05:00