chore(deps): update dependency ransack to v5 #81

Open
renovate wants to merge 1 commit from renovate/ransack-5.x into main
Collaborator

This PR contains the following updates:

Package Change Age Confidence
ransack (changelog) "~> 4.4" → "~> 5.0" age confidence

Release Notes

activerecord-hackery/ransack (ransack)

v5.0.2

Compare Source

Security release.

Fixes a denial of service: a crafted search key (a very long q[...] condition key or q[s] sort value) was parsed in quadratic time, letting an unauthenticated request exhaust CPU. Ransack now rejects an over-long key as invalid. Applies to any endpoint calling ransack; not mitigated by attribute allowlisting.

GHSA-j3f8-w227-4hh8. Also released as 5.0.2 (and fixed in 6.0.0).

v5.0.1: 5.0.1

Compare Source

Security fix: bounds the multiparameter position in search params (created_at(1i) and friends) and drops malformed keys, closing a memory-exhaustion denial of service where a crafted request such as q[created_at(100000000000i)]=1 made the server allocate an array of that size. Fixed in 4.4.2, 5.0.1 and 6.0.0. Reported by @​connorshea.

GHSA-vxc9-rm8f-p56j: https://github.com/activerecord-hackery/ransack/security/advisories/GHSA-vxc9-rm8f-p56j

v5.0.0

Compare Source

Added
  • [WIP/experimental] Add compatibility with Rails 5/master and Arel 7.

  • Update the Contributing Guide with detailed steps for
    contributing to Ransack.

  • Broaden the test suite database options in schema.rb and add
    code documentation.

  • Improve the header message when running tests.

    Jon Atack

  • Allow :wants_array to be set to false in the predicate options
    (#​32).

    Michael Pavling

  • Add a failing spec for issue
    #​374.

    Jamie Davidson, Jon Atack

Fixed
  • Stop relying on Active Record::relation#where_values which are deprecated
    in Rails 5.

  • Make the test for passing search arguments to a ransacker
    (ransacker_args) work correctly with Sqlite3.

    Jon Atack

Changed
  • Stop CI testing for Rails 3.0 to reduce the size of the Travis test matrix.

    Jon Atack


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [ransack](https://github.com/activerecord-hackery/ransack) ([changelog](https://github.com/activerecord-hackery/ransack/blob/main/CHANGELOG.md)) | `"~> 4.4"` → `"~> 5.0"` | ![age](https://developer.mend.io/api/mc/badges/age/rubygems/ransack/5.0.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/rubygems/ransack/4.4.3/5.0.2?slim=true) | --- ### Release Notes <details> <summary>activerecord-hackery/ransack (ransack)</summary> ### [`v5.0.2`](https://github.com/activerecord-hackery/ransack/releases/tag/v5.0.2) [Compare Source](https://github.com/activerecord-hackery/ransack/compare/v5.0.1...v5.0.2) Security release. Fixes a denial of service: a crafted search key (a very long `q[...]` condition key or `q[s]` sort value) was parsed in quadratic time, letting an unauthenticated request exhaust CPU. Ransack now rejects an over-long key as invalid. Applies to any endpoint calling `ransack`; not mitigated by attribute allowlisting. GHSA-j3f8-w227-4hh8. Also released as 5.0.2 (and fixed in 6.0.0). ### [`v5.0.1`](https://github.com/activerecord-hackery/ransack/releases/tag/v5.0.1): 5.0.1 [Compare Source](https://github.com/activerecord-hackery/ransack/compare/v5.0.0...v5.0.1) Security fix: bounds the multiparameter position in search params (`created_at(1i)` and friends) and drops malformed keys, closing a memory-exhaustion denial of service where a crafted request such as `q[created_at(100000000000i)]=1` made the server allocate an array of that size. Fixed in 4.4.2, 5.0.1 and 6.0.0. Reported by [@&#8203;connorshea](https://github.com/connorshea). GHSA-vxc9-rm8f-p56j: <https://github.com/activerecord-hackery/ransack/security/advisories/GHSA-vxc9-rm8f-p56j> ### [`v5.0.0`](https://github.com/activerecord-hackery/ransack/blob/HEAD/CHANGELOG.md#Version-165---2015-03-28---Rails-500-update) [Compare Source](https://github.com/activerecord-hackery/ransack/compare/v4.4.3...v5.0.0) ##### Added - \[WIP/experimental] Add compatibility with Rails 5/master and Arel 7. - Update the [Contributing Guide](CONTRIBUTING.md) with detailed steps for contributing to Ransack. - Broaden the test suite database options in `schema.rb` and add code documentation. - Improve the header message when running tests. *Jon Atack* - Allow `:wants_array` to be set to `false` in the predicate options ([#&#8203;32](https://github.com/activerecord-hackery/ransack/issues/32)). *Michael Pavling* - Add a failing spec for issue [#&#8203;374](https://github.com/activerecord-hackery/ransack/issues/374). *Jamie Davidson*, *Jon Atack* ##### Fixed - Stop relying on `Active Record::relation#where_values` which are deprecated in Rails 5. - Make the test for passing search arguments to a ransacker (`ransacker_args`) work correctly with Sqlite3. *Jon Atack* ##### Changed - Stop CI testing for Rails 3.0 to reduce the size of the Travis test matrix. *Jon Atack* </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45OS4wIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
chore(deps): update dependency ransack to v5
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
PR Triage / triage (pull_request) Successful in 4m13s
CI / test (pull_request) Successful in 7m56s
CI / scan_ruby (pull_request) Successful in 9m14s
CI / lint (pull_request) Successful in 8m40s
CI / system-test (pull_request) Successful in 9m30s
CI / coverage (pull_request) Failing after 4m14s
36135a7cb9
renovate force-pushed renovate/ransack-5.x from 36135a7cb9
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
PR Triage / triage (pull_request) Successful in 4m13s
CI / test (pull_request) Successful in 7m56s
CI / scan_ruby (pull_request) Successful in 9m14s
CI / lint (pull_request) Successful in 8m40s
CI / system-test (pull_request) Successful in 9m30s
CI / coverage (pull_request) Failing after 4m14s
to d5fa075117
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
CI / scan_ruby (pull_request) Successful in 4m49s
PR Triage / triage (pull_request) Successful in 3m48s
CI / lint (pull_request) Successful in 7m6s
CI / test (pull_request) Successful in 9m31s
CI / system-test (pull_request) Successful in 8m12s
CI / coverage (pull_request) Failing after 3m29s
2026-09-28 17:24:49 +00:00
Compare
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
CI / scan_ruby (pull_request) Successful in 4m49s
Required
Details
PR Triage / triage (pull_request) Successful in 3m48s
CI / lint (pull_request) Successful in 7m6s
Required
Details
CI / test (pull_request) Successful in 9m31s
Required
Details
CI / system-test (pull_request) Successful in 8m12s
Required
Details
CI / coverage (pull_request) Failing after 3m29s
Required
Details
Some required checks were not successful.
This branch is out-of-date with the base branch
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/ransack-5.x:renovate/ransack-5.x
git switch renovate/ransack-5.x
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
hobbypunk/rails-base_app!81
No description provided.