Skip to content

Releases: ualbertalib/library-cms

2.3.6

15 Apr 15:29
297d55a

Choose a tag to compare

What's Changed

Full Changelog: 2.3.5...2.3.6

2.3.5

25 Mar 16:43
60038db

Choose a tag to compare

What's Changed

  • Bump activesupport from 7.2.2.2 to 7.2.3.1 by @dependabot[bot] in #933
  • Above also bumped Rails and dependencies from 7.2.2.2 to 7.2.3.1

Full Changelog: 2.3.4...2.3.5

2.3.4

23 Mar 20:47
fd24b41

Choose a tag to compare

What's Changed

Full Changelog: 2.3.3...2.3.4

2.3.3

16 Mar 22:45
0ad4c2c

Choose a tag to compare

What's Changed

Full Changelog: 2.3.2...2.3.3

2.3.2

25 Feb 20:56
b9cae78

Choose a tag to compare

What's Changed

Full Changelog: 2.3.1...2.3.2

2.3.1

17 Feb 22:00
53c0ac0

Choose a tag to compare

What's Changed

Full Changelog: 2.3.0...2.3.1

2.3.0

04 Nov 17:58
c2624ed

Choose a tag to compare

What's Changed

Full Changelog: 2.2.2...2.3.0

2.2.2

27 Oct 20:06
80615ca

Choose a tag to compare

What's Changed

Security

  • CVE-2025-61780 Improper handling of headers in Rack::Sendfile may allow proxy bypass.
  • CVE-2025-61919 Unbounded read in Rack::Request form parsing can lead to memory exhaustion.

Full Changelog: 2.2.1...2.2.2

2.2.1

08 Oct 16:06
77ccbb3

Choose a tag to compare

What's Changed

Security:
CVE-2025-61772 Multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
CVE-2025-61771 Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
CVE-2025-61770 Unbounded multipart preamble buffering enables DoS (memory exhaustion)

Full Changelog: 2.2.0...2.2.1

2.2.0

07 Oct 16:59
6a0ba33

Choose a tag to compare

⚠️ Replaces deprecated secrets.yml with Config Gem -- required deployment changes

What's Changed

New Contributors

Full Changelog: 2.1.2...2.2.0