Bump rubyzip from 1.2.2 to 1.2.3
Bumps rubyzip from 1.2.2 to 1.2.3.
Release notes
Sourced from rubyzip's releases.
v1.2.3
- Allow tilde in zip entry names #391 (fixes regression in 1.2.2 from #376)
- Support frozen string literals in more files #390
- Require
pathname
explicitly #388 (fixes regression in 1.2.2 from #376)Tooling / Documentation:
- CI updates #392, #394
- Add changelog entry that was missing for last release #387
- Comment cleanup #385
Since the GitHub release information for 1.2.2 is missing, I will also include it here:
1.2.2
NB: This release drops support for extracting symlinks, because there was no clear way to support this securely. See https://github-redirect.dependabot.com/rubyzip/rubyzip/pull/376#issue-210954555 for details.
- Fix CVE-2018-1000544 #376 / #371
- Fix NoMethodError: undefined method `glob' #363
- Fix handling of stored files (i.e. files not using compression) with general purpose bit 3 set #358
- Fix
close
on StringIO-backed zip file #353- Add
Zip.force_entry_names_encoding
option #340- Update rubocop, apply auto-fixes, and fix regressions caused by said auto-fixes #332, #355
- Save temporary files to temporary directory (rather than current directory) #325
Tooling / Documentation:
Changelog
Sourced from rubyzip's changelog.
1.2.3
- Allow tilde in zip entry names #391 (fixes regression in 1.2.2 from #376)
- Support frozen string literals in more files #390
- Require
pathname
explicitly #388 (fixes regression in 1.2.2 from #376)Tooling / Documentation:
Commits
-
9d891f7
Fix link typo in changelog -
6f0b219
Merge pull request #393 from rubyzip/v1-2-3 -
ef516bd
Merge pull request #391 from jdleesmiller/fix-expand-path -
ada408d
Add #394 to changelog -
249775f
Merge pull request #394 from olleolleolle/patch-1 -
a8609e1
CI: update to latest MRI, drop a setting -
fb1c230
Bump version to 1.2.3 -
ad15c3c
Allow tilde in zip entry names -
8ece5c9
Merge pull request #392 from rubyzip/update-ci -
0f36838
Update ruby dependencies - Additional commits viewable in compare view