From patchwork Fri May 7 20:21:04 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Fabrice Fontaine X-Patchwork-Id: 1475667 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.138; helo=smtp1.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=I6C4gJ2v; dkim-atps=neutral Received: from smtp1.osuosl.org (smtp1.osuosl.org [140.211.166.138]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4FcML64Mvqz9sRK for ; Sat, 8 May 2021 06:21:50 +1000 (AEST) Received: from localhost (localhost [127.0.0.1]) by smtp1.osuosl.org (Postfix) with ESMTP id 68BDE844F2; Fri, 7 May 2021 20:21:48 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from smtp1.osuosl.org ([127.0.0.1]) by localhost (smtp1.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nE15G4NNVR20; Fri, 7 May 2021 20:21:47 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by smtp1.osuosl.org (Postfix) with ESMTP id DEE2E844DC; Fri, 7 May 2021 20:21:46 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from smtp2.osuosl.org (smtp2.osuosl.org [140.211.166.133]) by ash.osuosl.org (Postfix) with ESMTP id A63FF1BF377 for ; Fri, 7 May 2021 20:21:45 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by smtp2.osuosl.org (Postfix) with ESMTP id 932F0403B6 for ; Fri, 7 May 2021 20:21:45 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Authentication-Results: smtp2.osuosl.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from smtp2.osuosl.org ([127.0.0.1]) by localhost (smtp2.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EuhH6DU6BChd for ; Fri, 7 May 2021 20:21:44 +0000 (UTC) X-Greylist: whitelisted by SQLgrey-1.8.0 Received: from mail-wr1-x42b.google.com (mail-wr1-x42b.google.com [IPv6:2a00:1450:4864:20::42b]) by smtp2.osuosl.org (Postfix) with ESMTPS id 409094020A for ; Fri, 7 May 2021 20:21:44 +0000 (UTC) Received: by mail-wr1-x42b.google.com with SMTP id l2so10450183wrm.9 for ; Fri, 07 May 2021 13:21:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=IJfV5P8C91RmP4bflmea5EU2OV0pD6OdxQ57RyRGUl4=; b=I6C4gJ2vBY/LsKSyAp8m1RH+OKwmMOtasT9t/B2h31ppTNV1Fu/abMfc174FnqzxqU UPdL+MpLUDx2QfXSnMDC6Dq+VZfXhYHtqQt6Uy67JLYnZ1QxZgxjtE+SLw+iq8QQlyLf 90eYgHe4q8HFYvId58TxsxdvivaTRwmMwH2uAvsnfpLTbVqzJenthk5QqwEdR/nxnLED XAJVXuqh61esIRiyQ28zNYn/fW+Q4xA015a0LL2/3q39YWnGZasZ0o4KZBUI2UYdhTg3 tbYCxNFVvMvBWkmSzDJIzp20wZogqHn3F/wOLGPV7/AO8ZY8W3kPfh4StcVCVKiALf8/ yH/w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=IJfV5P8C91RmP4bflmea5EU2OV0pD6OdxQ57RyRGUl4=; b=j2od7JOsltx7808qdxcIPIPJjL6gt6j33d4qmN2piDkumFNcL7nZ8FXpzNm7TrovjB sdsM89CifjbRFNAvGLnnDhBnOAC5eZ917zqJs2z7HJRri7fV+15Kp+0TthqZohNa/kgF YbgAhxYQSODEs5eOtLmtZC/NT1DJBNESA2nDD5PTqJVw6333CEiR1Jq4p7plLG8X70pl BYog5mkMEykzIrUFUdzTRXV2HxbU8vbFu9OAHphggLik1jJcOxun+88G/f2+nB5/zvYl iBF35Gd6Em6pH63rNJwgMH9KNebU0vaoQP3zIIyK1VvLHvPygWUQ8mhBvbCK0l9YQRr6 qRDg== X-Gm-Message-State: AOAM5318EtXa18Z3leaQhptPmqhv762kiHMTIHSmGdzqEh/6VDQQBE3t JkFCCerWah+xmiC5WN/gYrV5hTJ0y5M= X-Google-Smtp-Source: ABdhPJzkqG9nDVHbW5zNC/Us0Gxz1fipQUcDimo+mHIMbcz4mcY+xK2o2orPyZMzgattwLGOw4uOxA== X-Received: by 2002:adf:e492:: with SMTP id i18mr14748517wrm.26.1620418902283; Fri, 07 May 2021 13:21:42 -0700 (PDT) Received: from kali.home (lfbn-ren-1-1383-171.w86-229.abo.wanadoo.fr. [86.229.230.171]) by smtp.gmail.com with ESMTPSA id s10sm9231279wru.55.2021.05.07.13.21.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 07 May 2021 13:21:41 -0700 (PDT) From: Fabrice Fontaine To: buildroot@buildroot.org Date: Fri, 7 May 2021 22:21:04 +0200 Message-Id: <20210507202104.2887487-1-fontaine.fabrice@gmail.com> X-Mailer: git-send-email 2.30.2 MIME-Version: 1.0 Subject: [Buildroot] [PATCH 1/1] package/ruby: security bump to version 3.0.1 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Fabrice Fontaine Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" This release includes security fixes: - CVE-2021-28965: XML round-trip vulnerability in REXML - CVE-2021-28966: Path traversal in Tempfile on Windows https://www.ruby-lang.org/en/news/2021/04/05/ruby-3-0-1-released/ Signed-off-by: Fabrice Fontaine --- package/ruby/ruby.hash | 4 ++-- package/ruby/ruby.mk | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/package/ruby/ruby.hash b/package/ruby/ruby.hash index ec9492aa5e..b79596e57a 100644 --- a/package/ruby/ruby.hash +++ b/package/ruby/ruby.hash @@ -1,5 +1,5 @@ -# https://www.ruby-lang.org/en/news/2020/12/25/ruby-3-0-0-released/ -sha256 68bfaeef027b6ccd0032504a68ae69721a70e97d921ff328c0c8836c798f6cb1 ruby-3.0.0.tar.xz +# https://www.ruby-lang.org/en/news/2021/04/05/ruby-3-0-1-released/ +sha512 97d2e883656060846b304368d9d836e2f3ef39859c36171c9398a0573818e4ed75bfd7460f901a9553f7f53518c505327a66e74f83704a881469f5ac61fe13d7 ruby-3.0.1.tar.xz # License files, Locally calculated sha256 274f8d7983052448e7fd691c81043465c92ee6fb7bd8ab3f20a7997862f2778e LEGAL sha256 967586d538a28955ec2541910cf63c5ac345fcdea94bfb1f1705a1f6eb36bcbb COPYING diff --git a/package/ruby/ruby.mk b/package/ruby/ruby.mk index c30ad691d1..fded7acebc 100644 --- a/package/ruby/ruby.mk +++ b/package/ruby/ruby.mk @@ -5,8 +5,8 @@ ################################################################################ RUBY_VERSION_MAJOR = 3.0 -RUBY_VERSION = $(RUBY_VERSION_MAJOR).0 -RUBY_VERSION_EXT = 3.0.0 +RUBY_VERSION = $(RUBY_VERSION_MAJOR).1 +RUBY_VERSION_EXT = 3.0.1 RUBY_SITE = http://cache.ruby-lang.org/pub/ruby/$(RUBY_VERSION_MAJOR) RUBY_SOURCE = ruby-$(RUBY_VERSION).tar.xz RUBY_DEPENDENCIES = host-pkgconf host-ruby