Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Any chance to release a new version? #28

Closed
tagliala opened this issue Sep 22, 2022 · 3 comments
Closed

Any chance to release a new version? #28

tagliala opened this issue Sep 22, 2022 · 3 comments

Comments

@tagliala
Copy link
Contributor

tagliala commented Sep 22, 2022

Hi, would it be possible to release a new version with the latest changes on master branch?

That would allow to update the ransack dependency to 3.x

I've also created:

@tagliala
Copy link
Contributor Author

tagliala commented Feb 3, 2023

Hi, this is a friendly bump for the merge of the aforementioned PRs

I will then proceed to check against Ransack main and add compatibility for 4.0, because of activerecord-hackery/ransack#1400 and a potential security issue (information disclosure)

Quoting from https://owasp.org/Top10/A01_2021-Broken_Access_Control/

A01:2021-Broken Access Control is the category with the most serious web
application security risk.

Allowing all attributes violates the principle of least privilege or deny by default,
where access should only be granted for particular capabilities, roles, or users.

@shioyama
Copy link
Owner

shioyama commented Mar 4, 2023

Sorry for taking so long, I've released 1.2.2!

@shioyama shioyama closed this as completed Mar 4, 2023
@tagliala
Copy link
Contributor Author

tagliala commented Mar 8, 2023

Thanks for the release, I will make a new PR to improve the changelog

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants