GNU bug report logs - #59585
[PATCH] gnu: ruby-3.0: Update to 3.1.3. [security fixes].

Previous Next

Package: guix-patches;

Reported by: Remco van 't Veer <remco <at> remworks.net>

Date: Fri, 25 Nov 2022 19:42:01 UTC

Severity: normal

Tags: patch

Done: Christopher Baines <mail <at> cbaines.net>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: help-debbugs <at> gnu.org (GNU bug Tracking System)
To: Christopher Baines <mail <at> cbaines.net>
Cc: tracker <at> debbugs.gnu.org
Subject: bug#59585: closed ([PATCH] gnu: ruby-3.0: Update to 3.1.3.
 [security fixes].)
Date: Tue, 06 Dec 2022 11:36:01 +0000
[Message part 1 (text/plain, inline)]
Your message dated Tue, 06 Dec 2022 11:35:25 +0000
with message-id <87sfhslq7c.fsf <at> cbaines.net>
and subject line Re: [bug#59585] [PATCH v2] gnu: ruby-3.1: Update to 3.1.3. [security fixes].
has caused the debbugs.gnu.org bug report #59585,
regarding [PATCH] gnu: ruby-3.0: Update to 3.1.3. [security fixes].
to be marked as done.

(If you believe you have received this mail in error, please contact
help-debbugs <at> gnu.org.)


-- 
59585: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=59585
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
From: Remco van 't Veer <remco <at> remworks.net>
To: guix-patches <at> gnu.org
Cc: Remco van 't Veer <remco <at> remworks.net>
Subject: [PATCH] gnu: ruby-3.0: Update to 3.1.3. [security fixes].
Date: Fri, 25 Nov 2022 20:40:52 +0100
Fixes: CVE-2021-33621: HTTP response splitting in CGI.

* gnu/packages/ruby.scm (ruby-3.1): Update to 3.1.3.
---
 gnu/packages/ruby.scm | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/gnu/packages/ruby.scm b/gnu/packages/ruby.scm
index b53aa02ef3..375b09fd72 100644
--- a/gnu/packages/ruby.scm
+++ b/gnu/packages/ruby.scm
@@ -225,7 +225,7 @@ (define-public ruby-3.0
 (define-public ruby-3.1
   (package
     (inherit ruby-3.0)
-    (version "3.1.2")
+    (version "3.1.3")
     (source
      (origin
        (method url-fetch)
@@ -234,7 +234,7 @@ (define-public ruby-3.1
                            "/ruby-" version ".tar.xz"))
        (sha256
         (base32
-         "0amzqczgvr51ilcqfgw0n41hrfanzi0wh8k6am3x5dm1z0bx046a"))))))
+         "06ipqz45qcs0y1273gk2gwslxwd7jgighz3mzbddzg16k29n3qaf"))))))
 
 (define-public ruby ruby-2.7)
 
-- 
2.38.1



[Message part 3 (message/rfc822, inline)]
From: Christopher Baines <mail <at> cbaines.net>
To: Remco van 't Veer <remco <at> remworks.net>
Cc: guix-patches <at> gnu.org, 59585-done <at> debbugs.gnu.org
Subject: Re: [bug#59585] [PATCH v2] gnu: ruby-3.1: Update to 3.1.3.
 [security fixes].
Date: Tue, 06 Dec 2022 11:35:25 +0000
[Message part 4 (text/plain, inline)]
Remco van 't Veer <remco <at> remworks.net> writes:

> Fixes: CVE-2021-33621: HTTP response splitting in CGI.
>
> * gnu/packages/ruby.scm (ruby-3.1): Update to 3.1.3.
> ---
>
> Oeps, sorry.  Copy paste error in commit message.
>
>  gnu/packages/ruby.scm | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)

Awesome, I've pushed this to master as
b573af1165081fa8be6afa15a5f54e148125c8f2.

Thanks,

Chris
[signature.asc (application/pgp-signature, inline)]

This bug report was last modified 2 years and 246 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.