Skip to content

Bump puma from 5.3.2 to 5.5.2

Milan requested to merge dependabot/bundler/puma-5.5.2 into master

Bumps puma from 5.3.2 to 5.5.2.

Release notes

Sourced from puma's releases.

5.5.2

Re-allows UTF-8 in HTTP header values

5.5.1

https://github.com/puma/puma/security/advisories/GHSA-48w2-rm65-62xx

5.5.0 - Zawgyi

5.5.0 / 2021-09-19

14871224

Zawgyi (Burmese: ဇော်ဂျီ) is a semi-immortal human alchemist and mystic with supernatural powers and often seen with a magic stick and a red hat. Zawgyi is one of the supernatural figures in Burmese mythology and folklore. Name chosen by new (Myanma!) contributor @ye-lin-aung.

The headline feature of this release is a new integration with the localhost gem. Localhost takes care of creating a self-signed SSL certificate for you in development. Require it in your config.ru:

# Sinatra
require './app'
require 'localhost/authority'
run Sinatra::Application

# Rails 
require 'localhost/authority' if Rails.env.development?
run MyRailsApp::Application

... and in the development environment, Puma will use a self-signed SSL cert generated by Localhost if no other cert is provided. Note: Make sure you set up Puma to run on an SSL socket: puma -b 'ssl://localhost:9292' config.ru

  • Features

    • Automatic SSL certificate provisioning for localhost, via localhost gem (#2610, #2257)
    • add support for the PROXY protocol (v1 only) (#2654, #2651)
    • Add a semantic CLI option for no config file (#2689)
  • Bugfixes

    • More elaborate exception handling - lets some dead pumas die. (#2700, #2699)
    • allow multiple after_worker_fork hooks (#2690)
    • Preserve BUNDLE_APP_CONFIG on worker fork (#2688, #2687)
  • Performance

    • Fix performance of server-side SSL connection close. (#2675)

5.4.0 - Super Flight

CasiopeaSuperFlightalbumcover

  • Features
    • Better/expanded names for threadpool threads (#2657)
    • Allow pkg_config for OpenSSL (#2648, #1412)
    • Add rack_url_scheme to Puma::DSL, allows setting of rack.url_scheme header (#2586, #2569)

... (truncated)

Changelog

Sourced from puma's changelog.

5.5.2 / 2021-10-12

  • Bugfixes
    • Allow UTF-8 in HTTP header values

5.5.1 / 2021-10-12

  • Security
    • Do not allow LF as a line ending in a header (CVE-2021-41136)

5.5.0 / 2021-09-19

  • Features

    • Automatic SSL certificate provisioning for localhost, via localhost gem (#2610, #2257)
    • add support for the PROXY protocol (v1 only) (#2654, #2651)
    • Add a semantic CLI option for no config file (#2689)
  • Bugfixes

    • More elaborate exception handling - lets some dead pumas die. (#2700, #2699)
    • allow multiple after_worker_fork hooks (#2690)
    • Preserve BUNDLE_APP_CONFIG on worker fork (#2688, #2687)
  • Performance

    • Fix performance of server-side SSL connection close. (#2675)

5.4.0 / 2021-07-28

  • Features

    • Better/expanded names for threadpool threads (#2657)
    • Allow pkg_config for OpenSSL (#2648, #1412)
    • Add rack_url_scheme to Puma::DSL, allows setting of rack.url_scheme header (#2586, #2569)
  • Bugfixes

    • Binder#parse - allow for symlinked unix path, add create_activated_fds debug ENV (#2643, #2638)
    • Fix deprecation warning: minissl.c - Use Random.bytes if available (#2642)
    • Client certificates: set session id context while creating SSLContext (#2633)
    • Fix deadlock issue in thread pool (#2656)
  • Refactor

    • Replace IO.select with IO#wait_* when checking a single IO (#2666)
Commits
  • a2bcda4 5.5.2
  • dc76d95 HTTP header field values: Allow all octets to be passed in as obscure data (#...
  • acdc3ae Merge pull request from GHSA-48w2-rm65-62xx
  • 61dd7f4 CI: Improve "set SSL" step name
  • 20dc923 Extract calls to purge_interrupt_queue (#2716)
  • cf991f6 Update instructions for GitHub actions [ci skip] (#2717)
  • 520dc92 Clean up some duplicated code (#2715)
  • 21e9a4a Clean up and format markdown documentation (#2714)
  • f0d73a7 Improve localhost SSL integration docs (#2712)
  • e2815b6 Reimplement delete environment tests (#2710)
  • Additional commits viewable in compare view

Merge request reports

Loading