A summary of data about the Ruby ecosystem.

Recent Releases of https://github.com/ruby/rubygems

https://github.com/ruby/rubygems - v3.1.6

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.1.5

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.9

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.6

Bug fixes:

  • Revert #2813. It broke the compatibility with 3.0.x versions.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.5

Enhancements:

  • Use env var to configure api key on push. Pull request #2559 by Luis
    Sagastume.
  • Unswallow uninstall error. Pull request #2707 by David Rodríguez.
  • Expose windows path normalization utility. Pull request #2767 by David
    Rodríguez.
  • Clean which command. Pull request #2801 by Luis Sagastume.
  • Upgrading S3 source signature to AWS SigV4. Pull request #2807 by
    Alexander Pakulov.
  • Remove misleading comment, no reason to move Gem.host to Gem::Util.
    Pull request #2811 by Luis Sagastume.
  • Drop support for 'gem env packageversion'. Pull request #2813 by Luis
    Sagastume.
  • Take into account just git tracked files in update_manifest rake task.
    Pull request #2816 by Luis Sagastume.
  • Remove TODO comment, there's no Gem::Dirs constant. Pull request #2819
    by Luis Sagastume.
  • Remove unused 'raise' from test_case. Pull request #2820 by Luis
    Sagastume.
  • Move TODO comment to an information comment. Pull request #2821 by Luis
    Sagastume.
  • Use File#open instead of Kernel#open in stub_specification.rb. Pull
    request #2834 by Luis Sagastume.
  • Make error code a gemcutter_utilities a constant. Pull request #2844 by
    Luis Sagastume.
  • Remove FIXME comment related to PathSupport. Pull request #2854 by Luis
    Sagastume.
  • Use gsub with Hash. Pull request #2860 by Kazuhiro NISHIYAMA.
  • Use the standard RUBY_ENGINE_VERSION instead of JRUBY_VERSION. Pull
    request #2864 by Benoit Daloze.
  • Do not mutate uri.query during s3 signature creation. Pull request #2874
    by Alexander Pakulov.
  • Fixup #2844. Pull request #2878 by SHIBATA Hiroshi.

Bug fixes:

  • Fix intermittent test error on Appveyor & Travis. Pull request #2568 by
    MSP-Greg.
  • Extend timeout on assert_self_install_permissions. Pull request #2605 by
    SHIBATA Hiroshi.
  • Better folder assertions. Pull request #2644 by David Rodríguez.
  • Fix default gem executable installation when folder is not bin/. Pull
    request #2649 by David Rodríguez.
  • Fix gem uninstall behavior. Pull request #2663 by Luis Sagastume.
  • Fix for large values in UID/GID fields in tar archives. Pull request
    #2780 by Alexey Shein.
  • Fixed task order for release. Pull request #2792 by SHIBATA Hiroshi.
  • Ignore GEMRC variable for test suite. Pull request #2837 by SHIBATA
    Hiroshi.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.4

Enhancements:

  • Add support for TruffleRuby #2612 by Benoit Daloze
  • Serve a more descriptive error when --no-ri or --no-rdoc are used #2572
    by Grey Baker
  • Improve test compatibility with CMake 2.8. Pull request #2590 by Vít
    Ondruch.
  • Restore gem build behavior and introduce the "-C" flag to gem build.
    Pull request #2596 by Luis Sagastume.
  • Enabled block call with util_set_arch. Pull request #2603 by SHIBATA
    Hiroshi.
  • Avoid rdoc hook when it's failed to load rdoc library. Pull request
    #2604 by SHIBATA Hiroshi.
  • Drop tests for legacy RDoc. Pull request #2608 by Nobuyoshi Nakada.
  • Update TODO comment. Pull request #2658 by Luis Sagastume.
  • Skip malicious extension test with mswin platform. Pull request #2670 by
    SHIBATA Hiroshi.
  • Check deprecated methods on release. Pull request #2673 by David
    Rodríguez.
  • Add steps to run bundler tests. Pull request #2680 by Aditya Prakash.
  • Skip temporary "No such host is known" error. Pull request #2684 by
    Takashi Kokubun.
  • Replaced aws-sdk-s3 instead of s3cmd. Pull request #2688 by SHIBATA
    Hiroshi.
  • Allow uninstall from symlinked GEM_HOME. Pull request #2720 by David
    Rodríguez.
  • Use current checkout in CI to uninstall RVM related gems. Pull request
    #2729 by David Rodríguez.
  • Update Contributor Covenant v1.4.1. Pull request #2751 by SHIBATA
    Hiroshi.
  • Added supported versions of Ruby. Pull request #2756 by SHIBATA Hiroshi.
  • Fix shadowing outer local variable warning. Pull request #2763 by Luis
    Sagastume.
  • Update the certificate files to make the test pass on Debian 10. Pull
    request #2777 by Yusuke Endoh.
  • Backport ruby core changes. Pull request #2778 by SHIBATA Hiroshi.

Bug fixes:

  • Test_gem.rb - intermittent failure fix. Pull request #2613 by MSP-Greg.
  • Fix sporadic CI failures. Pull request #2617 by David Rodríguez.
  • Fix flaky bundler version finder tests. Pull request #2624 by David
    Rodríguez.
  • Fix gem indexer tests leaking utility gems. Pull request #2625 by David
    Rodríguez.
  • Clean up default spec dir too. Pull request #2639 by David Rodríguez.
  • Fix 2.6.1 build against vendored bundler. Pull request #2645 by David
    Rodríguez.
  • Fix comment typo. Pull request #2664 by Luis Sagastume.
  • Fix comment of Gem::Specification#required_ruby_version=. Pull request
    #2732 by Alex Junger.
  • Fix TODOs. Pull request #2748 by David Rodríguez.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.3

Security fixes:

  • CVE-2019-8320: Delete directory using symlink when decompressing tar
  • CVE-2019-8321: Escape sequence injection vulnerability in verbose
  • CVE-2019-8322: Escape sequence injection vulnerability in gem owner
  • CVE-2019-8323: Escape sequence injection vulnerability in API response handling
  • CVE-2019-8324: Installing a malicious gem may lead to arbitrary code execution
  • CVE-2019-8325: Escape sequence injection vulnerability in errors

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.2

Enhancements:

  • Use Bundler-1.17.3. Pull request #2556 by SHIBATA Hiroshi.
  • Fix document flag description. Pull request #2555 by Luis Sagastume.

Bug fixes:

  • Fix tests when ruby --program-suffix is used without rubygems
    --format-executable. Pull request #2549 by Jeremy Evans.
  • Fix Gem::Requirement equality comparison when ~> operator is used. Pull
    request #2554 by Grey Baker.
  • Unset SOURCE_DATE_EPOCH in the test cases. Pull request #2558 by Sorah
    Fukumori.
  • Restore SOURCE_DATE_EPOCH. Pull request #2560 by SHIBATA Hiroshi.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.1

Bug fixes:

  • Ensure globbed files paths are expanded. Pull request #2536 by Tony Ta.
  • Dup the Dir.home string before passing it on. Pull request #2545 by
    Charles Oliver Nutter.
  • Added permissions to installed files for non-owners. Pull request #2546
    by SHIBATA Hiroshi.
  • Restore release task without hoe. Pull request #2547 by SHIBATA Hiroshi.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.0

Enhancements:

  • S3 source. Pull request #1690 by Aditya Prakash.
  • Download gems with threads. Pull request #1898 by André Arko.
  • Update to SPDX license list 3.0. Pull request #2152 by Mike Linksvayer.
  • [GSoC] Multi-factor feature for RubyGems. Pull request #2369 by Qiu
    Chaofan.
  • Use bundler 1.17.2. Pull request #2521 by SHIBATA Hiroshi.
  • Don't treat inaccessible working directories as build failures. Pull
    request #1135 by Pete.
  • Remove useless directory parameter from builders .build methods.
    [rebased]. Pull request #1433 by Kurtis Rainbolt-Greene.
  • Skipping more than one gem in pristine. Pull request #1592 by Henne
    Vogelsang.
  • Add info command to print information about an installed gem. Pull
    request #2023 by Colby Swandale.
  • Add --[no-]check-development option to cleanup command. Pull request
    #2061 by Lin Jen-Shin (godfat).
  • Show which gem referenced a missing gem. Pull request #2067 by Artem
    Khramov.
  • Prevent to delete to "bundler-" prefix gem like bundler-audit. Pull
    request #2086 by SHIBATA Hiroshi.
  • Fix rake install_test_deps once the rake clean_env does not exist. Pull
    request #2090 by Lucas Arantes.
  • Workaround common options mutation in Gem::Command test. Pull request
    #2098 by Thibault Jouan.
  • Extract a SpecificationPolicy validation class. Pull request #2101 by
    Olle Jonsson.
  • Handle environment that does not have flock system call. Pull request
    #2107 by SHIBATA Hiroshi.
  • Handle the explain option in gem update. Pull request #2110 by Colby
    Swandale.
  • Add Gem.operating_system_defaults to allow packagers to override
    defaults. Pull request #2116 by Vít Ondruch.
  • Update for compatibility with new minitest. Pull request #2118 by
    MSP-Greg.
  • Make Windows bin stubs portable. Pull request #2119 by MSP-Greg.
  • Avoid to warnings about gemspec loadings in rubygems tests. Pull request
    #2125 by SHIBATA Hiroshi.
  • Set whether bundler is used for gemdeps with an environmental variable.
    Pull request #2126 by SHIBATA Hiroshi.
  • Titleize "GETTING HELP" in readme. Pull request #2136 by Colby Swandale.
  • Improve the error message given when using --version with multiple gems
    in the install command. Pull request #2137 by Colby Swandale.
  • Use File.open instead of open. Pull request #2142 by SHIBATA
    Hiroshi.
  • Gem::Util.traverse_parents should not crash on permissions error. Pull
    request #2147 by Robert Ulejczyk.
  • [Installer] Avoid a #mkdir race condition. Pull request #2148 by Samuel
    Giddins.
  • Allow writing gemspecs from gem unpack to location specified by target
    option. Pull request #2150 by Colby Swandale.
  • Raise errors in gem uninstall when a file in a gem could not be
    removed . Pull request #2154 by Colby Swandale.
  • Remove PID from gem index directory. Pull request #2155 by SHIBATA
    Hiroshi.
  • Nil guard on Gem::Specification. Pull request #2164 by SHIBATA
    Hiroshi.
  • Skip broken test with macOS platform. Pull request #2167 by SHIBATA
    Hiroshi.
  • Support option for --destdir with upgrade installer. Pull request
    #2169 by SHIBATA Hiroshi.
  • To use constant instead of hard-coded version. Pull request #2171 by
    SHIBATA Hiroshi.
  • Add Rake task to install dev dependencies. Pull request #2173 by Ellen
    Marie Dash.
  • Add new sections to the README and explanation of what RubyGems is.
    Pull request #2174 by Colby Swandale.
  • Prefer to use Numeric#zero? instead of == 0. Pull request #2176 by
    SHIBATA Hiroshi.
  • Ignore performance test of version regexp pattern. Pull request #2179 by
    SHIBATA Hiroshi.
  • Ignore .DS_Store files in the update_manifest task. Pull request #2199
    by Colby Swandale.
  • Allow building gems without having to be in the gem folder . Pull
    request #2204 by Colby Swandale.
  • Added coverage ability used by simplecov. Pull request #2207 by SHIBATA
    Hiroshi.
  • Improve invalid proxy error message. Pull request #2217 by Luis
    Sagastume.
  • Simplify home directory detection and platform condition. Pull request
    #2218 by SHIBATA Hiroshi.
  • Permission options. Pull request #2219 by Nobuyoshi Nakada.
  • Improve gemspec and package task. Pull request #2220 by SHIBATA Hiroshi.
  • Prefer to use util_spec in Gem::TestCase. Pull request #2227 by
    SHIBATA Hiroshi.
  • [Requirement] Treat requirements with == versions as equal. Pull
    request #2230 by Samuel Giddins.
  • Add a note for the non-semantically versioned case. Pull request #2242
    by David Rodríguez.
  • Keep feature names loaded in the block. Pull request #2261 by Nobuyoshi
    Nakada.
  • Tweak warning recommendation. Pull request #2266 by David Rodríguez.
  • Show git path in gem env. Pull request #2268 by Luis Sagastume.
  • Add --env-shebang flag to setup command. Pull request #2271 by James
    Myers.
  • Support SOURCE_DATE_EPOCH to make gem spec reproducible. Pull request
    #2278 by Levente Polyak.
  • Chdir back to original directory when building an extension fails. Pull
    request #2282 by Samuel Giddins.
  • [Rakefile] Add a default task that runs the tests. Pull request #2283 by
    Samuel Giddins.
  • Support SOURCE_DATE_EPOCH to make gem tar reproducible. Pull request
    #2289 by Levente Polyak.
  • Reset hooks in test cases. Pull request #2297 by Samuel Giddins.
  • Minor typo: nokogiri. Pull request #2298 by Darshan Baid.
  • Ignore vendored molinillo from code coverage. Pull request #2302 by
    SHIBATA Hiroshi.
  • Support IO.copy_stream. Pull request #2303 by okkez.
  • Prepare beta release. Pull request #2304 by SHIBATA Hiroshi.
  • Add error message when trying to open a default gem. Pull request #2307
    by Luis Sagastume.
  • Add alias command 'i' for 'install' command. Pull request #2308 by
    ota42y.
  • Cleanup rdoc task in Rakefile. Pull request #2318 by SHIBATA Hiroshi.
  • Add testcase to test_gem_text.rb. Pull request #2329 by Oliver.
  • Gem build strict option. Pull request #2332 by David Rodríguez.
  • Make spec reset more informative. Pull request #2333 by Luis Sagastume.
  • [Rakefile] Set bundler build metadata when doing a release. Pull request
    #2335 by Samuel Giddins.
  • Speed up globbing relative to given directories. Pull request #2336 by
    Samuel Giddins.
  • Remove semver gem build warning. Pull request #2351 by David Rodríguez.
  • Expand symlinks in gem path. Pull request #2352 by Benoit Daloze.
  • Normalize comment indentations. Pull request #2353 by David Rodríguez.
  • Add bindir flag to pristine. Pull request #2361 by Luis Sagastume.
  • Add --user-install behaviour to cleanup command. Pull request #2362 by
    Luis Sagastume.
  • Allow build options to be passed to Rake. Pull request #2382 by Alyssa
    Ross.
  • Add --re-sign flag to cert command. Pull request #2391 by Luis
    Sagastume.
  • Fix "interpreted as grouped expression" warning. Pull request #2399 by
    Colby Swandale.
  • [Gem::Ext::Builder] Comments to aid future refactoring. Pull request
    #2405 by Ellen Marie Dash.
  • Move CONTRIBUTING.rdoc and POLICIES.rdoc documents to markdown. Pull
    request #2412 by Colby Swandale.
  • Improve certificate expiration defaults. Pull request #2420 by Luis
    Sagastume.
  • Freeze all possible constants. Pull request #2422 by Colby Swandale.
  • Fix bundler rubygems binstub not properly looking for bundler. Pull
    request #2426 by David Rodríguez.
  • Make sure rubygems never leaks to another installation. Pull request
    #2427 by David Rodríguez.
  • Update README.md. Pull request #2428 by Marc-André Lafortune.
  • Restrict special chars from prefixing new gem names. Pull request #2432
    by Luis Sagastume.
  • This removes support for dynamic API backend lookup via DNS SRV records.
    Pull request #2433 by Arlandis Word.
  • Fix link to CONTRIBUTING.md doc. Pull request #2434 by Arlandis Word.
  • Support Keyword args with Psych. Pull request #2439 by SHIBATA Hiroshi.
  • Bug/kernel#warn uplevel. Pull request #2442 by Nobuyoshi Nakada.
  • Improve certificate error message. Pull request #2454 by Luis Sagastume.
  • Update gem open command help text. Pull request #2458 by Aditya Prakash.
  • Uninstall with versions. Pull request #2466 by David Rodríguez.
  • Add output option to build command. Pull request #2501 by Colby
    Swandale.
  • Move rubocop into a separate stage in travis ci. Pull request #2510 by
    Colby Swandale.
  • Ignore warnings with test_gem_specification.rb. Pull request #2523 by
    SHIBATA Hiroshi.
  • Support the environment without OpenSSL. Pull request #2528 by SHIBATA
    Hiroshi.

Bug fixes:

  • Fix undefined method error when printing alert. Pull request #1884 by
    Robert Ross.
  • Frozen string fix - lib/rubygems/bundler_version_finder.rb. Pull request
    #2115 by MSP-Greg.
  • Fixed typos. Pull request #2143 by SHIBATA Hiroshi.
  • Fix regression of destdir on Windows platform. Pull request #2178 by
    SHIBATA Hiroshi.
  • Fixed no assignment variables about default gems installation. Pull
    request #2181 by SHIBATA Hiroshi.
  • Fix spelling errors in the README. Pull request #2187 by Colby Swandale.
  • Missing comma creates ambiguous meaning. Pull request #2190 by Clifford
    Heath.
  • Fix getting started instructions. Pull request #2198 by Luis Sagastume.
  • Fix rubygems dev env. Pull request #2201 by Luis Sagastume.
  • Fix #1470: generate documentation when --install-dir is present. Pull
    request #2229 by Elias Hernandis.
  • Fix activation when multiple platforms installed. Pull request #2339 by
    MSP-Greg.
  • Fix required_ruby_version with prereleases and improve error message.
    Pull request #2344 by David Rodríguez.
  • Update tests for 'newer' Windows builds. Pull request #2348 by MSP-Greg.
  • Fix broken rubocop task by upgrading to 0.58.1. Pull request #2356 by
    David Rodríguez.
  • Gem::Version should handle nil like it used to before. Pull request
    #2363 by Luis Sagastume.
  • Avoid need of C++ compiler to pass the test suite. Pull request #2367 by
    Vít Ondruch.
  • Fix auto resign expired certificate. Pull request #2380 by Luis
    Sagastume.
  • Skip permissions-dependent test when root. Pull request #2386 by Alyssa
    Ross.
  • Fix test that depended on /usr/bin being in PATH. Pull request #2387 by
    Alyssa Ross.
  • Fixed test fail with mswin environment. Pull request #2390 by SHIBATA
    Hiroshi.
  • Fix broken builds using the correct rubocop version. Pull request #2396
    by Luis Sagastume.
  • Fix extension builder failure when verbose. Pull request #2457 by Sorah
    Fukumori.
  • Fix test warnings. Pull request #2472 by MSP-Greg.
  • The test suite of bundler is not present ruby description. Pull request
    #2484 by SHIBATA Hiroshi.
  • Fix crash on certain gemspecs. Pull request #2506 by David Rodríguez.
  • Fixed test fails with the newer version of OpenSSL. Pull request #2507
    by SHIBATA Hiroshi.
  • Fix broken symlink that points to ../*. Pull request #2516 by Akira
    Matsuda.
  • Fix remote fetcher tests. Pull request #2520 by Luis Sagastume.
  • Fix tests when --program-suffix and similar ruby configure options are
    used. Pull request #2529 by Jeremy Evans.

Breaking changes:

  • IO.binread is not provided at Ruby 1.8. Pull request #2093 by SHIBATA
    Hiroshi.
  • Ignored to publish rdoc documentation of rubygems for
    docs.seattlerb.org. Pull request #2105 by SHIBATA Hiroshi.
  • Support pre-release RubyGems. Pull request #2128 by SHIBATA Hiroshi.
  • Relax minitest version for 5. Pull request #2131 by SHIBATA Hiroshi.
  • Remove zentest from dev dependency. Pull request #2132 by SHIBATA
    Hiroshi.
  • Remove hoe for test suite. Pull request #2160 by SHIBATA Hiroshi.
  • Cleanup deprecated tasks. Pull request #2162 by SHIBATA Hiroshi.
  • Drop to support Ruby < 2.2. Pull request #2182 by SHIBATA Hiroshi.
  • Cleanup deprecated style. Pull request #2193 by SHIBATA Hiroshi.
  • Remove CVEs from the rubygems repo. Pull request #2195 by Colby
    Swandale.
  • Removed needless condition for old version of ruby. Pull request #2206
    by SHIBATA Hiroshi.
  • Removed deprecated methods over the limit day. Pull request #2216 by
    SHIBATA Hiroshi.
  • Remove syck support. Pull request #2222 by SHIBATA Hiroshi.
  • Removed needless condition for Encoding. Pull request #2223 by SHIBATA
    Hiroshi.
  • Removed needless condition for String#force_encoding. Pull request #2225
    by SHIBATA Hiroshi.
  • Removed needless OpenSSL patch for Ruby 1.8. Pull request #2243 by
    SHIBATA Hiroshi.
  • Removed compatibility code for Ruby 1.9.2. Pull request #2244 by SHIBATA
    Hiroshi.
  • Removed needless version condition for the old ruby. Pull request #2252
    by SHIBATA Hiroshi.
  • Remove needless define/respond_to condition. Pull request #2255 by
    SHIBATA Hiroshi.
  • Use File.realpath directly in Gem::Package. Pull request #2284 by
    SHIBATA Hiroshi.
  • Removed needless condition for old versions of Ruby. Pull request #2286
    by SHIBATA Hiroshi.
  • Remove the --rdoc and --ri options from install/update. Pull request
    #2354 by Colby Swandale.
  • Move authors assigner to required attributes section of
    Gem::Specification. Pull request #2406 by Grey Baker.
  • Remove rubyforge_page functionality. Pull request #2436 by Nick
    Schwaderer.
  • Drop ruby 1.8 support and use IO.popen. Pull request #2441 by Nobuyoshi
    Nakada.
  • Drop ruby 2.2 support. Pull request #2487 by David Rodríguez.
  • Remove some old compatibility code. Pull request #2488 by David
    Rodríguez.
  • Remove .document from src. Pull request #2489 by Colby Swandale.
  • Remove old version support. Pull request #2493 by Nobuyoshi Nakada.
  • [BudlerVersionFinder] set .filter! and .compatible? to match only on
    major versions. Pull request #2515 by Colby Swandale.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.0.beta3

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.0.beta2

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v3.0.0.beta1

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.11

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.10

Enhancements:

  • Fix bundler rubygems binstub not properly looking for bundler. Pull request #2426
    by David Rodríguez.
  • [BudlerVersionFinder] set .filter! and .compatible? to match only on major versions.
    Pull request #2515 by Colby Swandale.
  • Update for compatibility with new minitest. Pull request #2118 by MSP-Greg.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.9

Security fixes:

  • CVE-2019-8320: Delete directory using symlink when decompressing tar
  • CVE-2019-8321: Escape sequence injection vulnerability in verbose
  • CVE-2019-8322: Escape sequence injection vulnerability in gem owner
  • CVE-2019-8323: Escape sequence injection vulnerability in API response handling
  • CVE-2019-8324: Installing a malicious gem may lead to arbitrary code execution
  • CVE-2019-8325: Escape sequence injection vulnerability in errors

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.8

Enhancements:

  • [Requirement] Treat requirements with == versions as equal. Pull
    request #2230 by Samuel Giddins.
  • Fix exec_name documentation. Pull request #2239 by Luis Sagastume.
  • [TarHeader] Extract the empty header into a constant. Pull request #2247
    by Samuel Giddins.
  • Simplify the code that lets us call the original, non-monkeypatched
    Kernel#require. Pull request #2267 by Leon Miller-Out.
  • Add install alias documentation. Pull request #2320 by ota42y.
  • [Rakefile] Set bundler build metadata when doing a release. Pull request
    #2335 by Samuel Giddins.
  • Backport commits from ruby core . Pull request #2347 by SHIBATA Hiroshi.
  • Sign in to the correct host before push. Pull request #2366 by Luis
    Sagastume.
  • Bump bundler-1.16.4. Pull request #2381 by SHIBATA Hiroshi.
  • Improve bindir flag description. Pull request #2383 by Luis Sagastume.
  • Update bundler-1.16.6. Pull request #2423 by SHIBATA Hiroshi.

Bug fixes:

  • Fix #1470: generate documentation when --install-dir is present. Pull
    request #2229 by Elias Hernandis.
  • Fix no proxy checking. Pull request #2249 by Luis Sagastume.
  • Validate SPDX license exceptions. Pull request #2257 by Mikit.
  • Retry api specification spec with original platform. Pull request #2275
    by Luis Sagastume.
  • Fix approximate recommendation with prereleases. Pull request #2345 by
    David Rodríguez.
  • Gem::Version should handle nil like it used to before. Pull request
    #2363 by Luis Sagastume.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.7

Enhancements:

  • [RequestSet] Only suggest a gem version with an installable platform.
    Pull request #2175 by Samuel Giddins.
  • Fixed no assignment variables about default gems installation. Pull
    request #2181 by SHIBATA Hiroshi.
  • Backport improvements for test-case from Ruby core. Pull request #2189
    by SHIBATA Hiroshi.
  • Fix ruby warnings in test suite. Pull request #2205 by Colby Swandale.
  • To use Gem::Specification#bindir of bundler instead of hard coded path.
    Pull request #2208 by SHIBATA Hiroshi.
  • Update gem push --help description. Pull request #2215 by Luis
    Sagastume.
  • Backport ruby core commits. Pull request #2264 by SHIBATA Hiroshi.

Bug fixes:

  • Frozen string fix - lib/rubygems/bundler_version_finder.rb. Pull request
    #2115 by MSP-Greg.
  • Fixed tempfile leak for RubyGems 2.7.6. Pull request #2194 by SHIBATA
    Hiroshi.
  • Add missing requires. Pull request #2196 by David Rodríguez.
  • Fix Gem::Version.correct?. Pull request #2203 by Masato Nakamura.
  • Fix verify_entry regex for metadata. Pull request #2212 by Luis
    Sagastume.
  • Fix path checks for case insensitive filesystem. Pull request #2211 by
    Lars Kanis.

Deprecations:

  • Deprecate unused code before removing them at #1524. Pull request #2197
    by SHIBATA Hiroshi.
  • Deprecate for rubygems 3. Pull request #2214 by SHIBATA Hiroshi.
  • Mark deprecation to ubygems.rb for RubyGems 4. Pull request #2269 by
    SHIBATA Hiroshi.

Breaking changes:

  • Update bundler-1.16.2. Pull request #2291 by SHIBATA Hiroshi.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.6

Security fixes:

  • Prevent path traversal when writing to a symlinked basedir outside of the root.
    Discovered by nmalkin, fixed by Jonathan Claudius and Samuel Giddins.
  • Fix possible Unsafe Object Deserialization Vulnerability in gem owner.
    Fixed by Jonathan Claudius.
  • Strictly interpret octal fields in tar headers.
    Discovered by plover, fixed by Samuel Giddins.
  • Raise a security error when there are duplicate files in a package.
    Discovered by plover, fixed by Samuel Giddins.
  • Enforce URL validation on spec homepage attribute.
    Discovered by Yasin Soliman, fixed by Jonathan Claudius.
  • Mitigate XSS vulnerability in homepage attribute when displayed via gem server.
    Discovered by Yasin Soliman, fixed by Jonathan Claudius.
  • Prevent Path Traversal issue during gem installation.
    Discovered by nmalkin.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.5

Bug fixes:

  • To use bundler-1.16.1 #2121 by SHIBATA Hiroshi.
  • Fixed leaked FDs. Pull request #2127 by Nobuyoshi Nakada.
  • Support option for --destdir with upgrade installer. #2169 by Thibault Jouan.
  • Remove PID from gem index directory. #2155 by SHIBATA Hiroshi.
  • Avoid a #mkdir race condition #2148 by Samuel Giddins.
  • Gem::Util.traverse_parents should not crash on permissions error #2147 by Robert Ulejczyk.
  • Use File.open instead of open. #2142 by SHIBATA Hiroshi.
  • Set whether bundler is used for gemdeps with an environmental variable #2126 by SHIBATA Hiroshi.
  • Fix undefined method error when printing alert #1884 by Robert Ross.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.4

Bug fixes:

  • Fixed leaked FDs. Pull request #2127 by Nobuyoshi Nakada.
  • Avoid to warnings about gemspec loadings in rubygems tests. Pull request
    #2125 by SHIBATA Hiroshi.
  • Fix updater with rubygems-2.7.3 Pull request #2124 by SHIBATA Hiroshi.
  • Handle environment that does not have flock system call. Pull request
    #2107 by SHIBATA Hiroshi.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.3

Enhancements:

  • Removed needless version lock. Pull request #2074 by SHIBATA Hiroshi.
  • Add --[no-]check-development option to cleanup command. Pull request
    #2061 by Lin Jen-Shin (godfat).
  • Merge glob pattern using braces. Pull request #2072 by Kazuhiro
    NISHIYAMA.
  • Removed warnings of unused variables. Pull request #2084 by SHIBATA
    Hiroshi.
  • Call SPDX.org using HTTPS. Pull request #2102 by Olle Jonsson.
  • Remove multi load warning from plugins documentation. Pull request #2103
    by Thibault Jouan.

Bug fixes:

  • Fix test failure on Alpine Linux. Pull request #2079 by Ellen Marie
    Dash.
  • Avoid encoding issues by using binread in setup. Pull request #2089 by
    Mauro Morales.
  • Fix rake install_test_deps once the rake clean_env does not exist. Pull
    request #2090 by Lucas Oliveira.
  • Prevent to delete to "bundler-" prefix gem like bundler-audit. Pull
    request #2086 by SHIBATA Hiroshi.
  • Generate .bat files on Windows platform. Pull request #2094 by SHIBATA
    Hiroshi.
  • Workaround common options mutation in Gem::Command test. Pull request
    #2098 by Thibault Jouan.
  • Check gems dir existence before removing bundler. Pull request #2104 by
    Thibault Jouan.
  • Use setup command --regenerate-binstubs option flag. Pull request #2099
    by Thibault Jouan.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.1

Bug fixes:

  • Fix gem update --system with RubyGems 2.7+. Pull request #2054 by
    Samuel Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.7.0

Enhancements:

  • Update vendored bundler-1.16.0. Pull request #2051 by Samuel Giddins.
  • Use Bundler for Gem.use_gemdeps. Pull request #1674 by Samuel Giddins.
  • Add command signin to gem CLI. Pull request #1944 by Shiva Bhusal.
  • Add Logout feature to CLI. Pull request #1938 by Shiva Bhusal.
  • Added message to uninstall command for gem that is not installed. Pull
    request #1979 by anant anil kolvankar.
  • Add --trust-policy option to unpack command. Pull request #1718 by
    Nobuyoshi Nakada.
  • Show default gems for all platforms. Pull request #1685 by Konstantin
    Shabanov.
  • Add Travis and Appveyor build status to README. Pull request #1918 by
    Jun Aruga.
  • Remove warning no email specified when no email. Pull request #1675 by
    Leigh McCulloch.
  • Improve -rubygems performance. Pull request #1801 by Samuel Giddins.
  • Improve the performance of Kernel#require. Pull request #1678 by Samuel
    Giddins.
  • Improve user-facing messages by consistent casing of Ruby/RubyGems. Pull
    request #1771 by John Labovitz.
  • Improve error message when Gem::RuntimeRequirementNotMetError is raised.
    Pull request #1789 by Luis Sagastume.
  • Code Improvement: Inheritance corrected. Pull request #1942 by Shiva
    Bhusal.
  • [Source] Autoload fileutils. Pull request #1906 by Samuel Giddins.
  • Use Hash#fetch instead of if/else in Gem::ConfigFile. Pull request #1824
    by Daniel Berger.
  • Require digest when it is used. Pull request #2006 by Samuel Giddins.
  • Do not index the doc folder in the update_manifest task. Pull request
    #2031 by Colby Swandale.
  • Don't use two postfix conditionals on one line. Pull request #2038 by
    Ellen Marie Dash.
  • [SafeYAML] Avoid warning when Gem::Deprecate.skip is set. Pull request
    #2034 by Samuel Giddins.
  • Update gem yank description. Pull request #2009 by David Radcliffe.
  • Fix formatting of installation instructions in README. Pull request
    #2018 by Jordan Danford.
  • Do not use #quick_spec internally. Pull request #1733 by Jon Moss.
  • Switch from docs to guides reference. Pull request #1886 by Jonathan
    Claudius.
  • Happier message when latest version is already installed. Pull request
    #1956 by Jared Beck.
  • Update specification reference docs. Pull request #1960 by Grey Baker.
  • Allow Gem.finish_resolve to respect already-activated specs. Pull
    request #1910 by Samuel Giddins.
  • Update cryptography for Gem::Security. Pull request #1691 by Sylvain
    Daubert.
  • Don't output mkmf.log message if compilation didn't fail. Pull request
    #1808 by Jeremy Evans.
  • Matches_for_glob - remove root path. Pull request #2010 by ahorek.
  • Gem::Resolver#search_for update for reliable searching/sorting. Pull
    request #1993 by MSP-Greg.
  • Allow local installs with transitive prerelease requirements. Pull
    request #1990 by Samuel Giddins.
  • Small style fixes to Installer Set. Pull request #1985 by Arthur
    Marzinkovskiy.
  • Setup cmd: Avoid terminating option string w/ dot. Pull request #1825 by
    Olle Jonsson.
  • Warn when no files are set. Pull request #1773 by Aidan Coyle.
  • Ensure to_spec falls back on prerelease specs. Pull request #1755 by
    André Arko.
  • [Specification] Eval setting default attributes in #initialize. Pull
    request #1739 by Samuel Giddins.
  • Sort ordering of sources is preserved. Pull request #1633 by Nathan
    Ladd.
  • Retry with :prerelease when no suggestions are found. Pull request #1696
    by Aditya Prakash.
  • [Rakefile] Run git submodule update --init in rake newb. Pull
    request #1694 by Samuel Giddins.
  • [TestCase] Address comments around ui changes. Pull request #1677 by
    Samuel Giddins.
  • Eagerly resolve in activate_bin_path. Pull request #1666 by Samuel
    Giddins.
  • [Version] Make hash based upon canonical segments. Pull request #1659 by
    Samuel Giddins.
  • Add Ruby Together CTA, rearrange README a bit. Pull request #1775 by
    Michael Bernstein.
  • Update Contributing.rdoc with new label usage. Pull request #1716 by
    Lynn Cyrin.
  • Add --host sample to help. Pull request #1709 by Code Ahss.
  • Add a helpful suggestion when gem install fails due to required_rub….
    Pull request #1697 by Samuel Giddins.
  • Add cert expiration length flag. Pull request #1725 by Luis Sagastume.
  • Add submodule instructions to manual install. Pull request #1727 by
    Joseph Frazier.
  • Allow usage of multiple --version operators. Pull request #1546 by
    James Wen.
  • Warn when requiring deprecated files. Pull request #1939 by Ellen Marie
    Dash.

Deprecations:

  • Deprecate Gem::InstallerTestCase#util_gem_bindir and
    Gem::InstallerTestCase#util_gem_dir. Pull request #1729 by Jon Moss.
  • Deprecate passing options to Gem::GemRunner. Pull request #1730 by Jon
    Moss.
  • Add deprecation for Gem#datadir. Pull request #1732 by Jon Moss.
  • Add deprecation warning for Gem::DependencyInstaller#gems_to_install.
    Pull request #1731 by Jon Moss.

Breaking changes:

  • Use -rrubygems instead of -rubygems.rb. Because ubygems.rb is
    unavailable on Ruby 2.5. Pull request #2028 #2027 #2029
    by SHIBATA Hiroshi.
  • Update Code of Conduct to Contributor Covenant v1.4.0. Pull request
    #1796 by Matej.

Bug fixes:

  • Fix issue for MinGW / MSYS2 builds and testing. Pull request #1876 by
    MSP-Greg.
  • Fixed broken links and overzealous URL encoding in gem server. Pull
    request #1809 by Nicole Orchard.
  • Fix a typo. Pull request #1722 by Koichi ITO.
  • Fix error message Gem::Security::Policy. Pull request #1724 by Nobuyoshi
    Nakada.
  • Fixing links markdown formatting in README. Pull request #1791 by Piotr
    Kuczynski.
  • Fix failing Bundler 1.8.7 CI builds. Pull request #1820 by Samuel
    Giddins.
  • Fixed test broken on ruby-head . Pull request #1842 by SHIBATA Hiroshi.
  • Fix typos with misspell. Pull request #1846 by SHIBATA Hiroshi.
  • Fix gem open to open highest version number rather than lowest. Pull
    request #1877 by Tim Pope.
  • Fix test_self_find_files_with_gemfile to sort expected files. Pull
    request #1878 by Kazuaki Matsuo.
  • Fix typos in CONTRIBUTING.rdoc. Pull request #1909 by Mark Sayson.
  • Fix some small documentation issues in installer. Pull request #1972 by
    Colby Swandale.
  • Fix links in Policies document. Pull request #1964 by Alyssa Ross.
  • Fix NoMethodError on bundler/inline environment. Pull request #2042 by
    SHIBATA Hiroshi.
  • Correct comments for Gem::InstallerTestCase#setup. Pull request #1741 by
    MSP-Greg.
  • Use File.expand_path for certification and key location. Pull request
    #1987 by SHIBATA Hiroshi.
  • Rescue EROFS. Pull request #1417 by Nobuyoshi Nakada.
  • Fix spelling of 'vulnerability'. Pull request #2022 by Philip Arndt.
  • Fix metadata link key names. Pull request #1896 by Aditya Prakash.
  • Fix a typo in uninstall_command.rb. Pull request #1934 by Yasuhiro
    Horimoto.
  • Gem::Requirement.create treat arguments as variable-length. Pull request
    #1830 by Toru YAGI.
  • Display an explanation when rake encounters an ontological problem. Pull
    request #1982 by Wilson Bilkovich.
  • [Server] Handle gems with names ending in -\d. Pull request #1926 by
    Samuel Giddins.
  • [InstallerSet] Avoid reloading all local gems multiple times during
    dependency resolution. Pull request #1925 by Samuel Giddins.
  • Modify the return value of Gem::Version.correct?. Pull request #1916 by
    Tsukuru Tanimichi.
  • Validate metadata link keys. Pull request #1834 by Aditya Prakash.
  • Add changelog to metadata validation. Pull request #1885 by Aditya
    Prakash.
  • Replace socket error text message. Pull request #1823 by Daniel Berger.
  • Raise error if the email is invalid when building cert. Pull request
    #1779 by Luis Sagastume.
  • [StubSpecification] Don’t iterate through all loaded specs in #to_spec.
    Pull request #1738 by Samuel Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.14

Security fixes:

  • Whitelist classes and symbols that are in loaded YAML.
    See CVE-2017-0903 for full details.
    Fix by Aaron Patterson.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.13

Security fixes:

  • Fix a DNS request hijacking vulnerability. (CVE-2017-0902)
    Discovered by Jonathan Claudius, fix by Samuel Giddins.
  • Fix an ANSI escape sequence vulnerability. (CVE-2017-0899)
    Discovered by Yusuke Endoh, fix by Evan Phoenix.
  • Fix a DOS vulnerability in the query command. (CVE-2017-0900)
    Discovered by Yusuke Endoh, fix by Samuel Giddins.
  • Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files. (CVE-2017-0901)
    Discovered by Yusuke Endoh, fix by Samuel Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.12

Bug fixes:

  • Fix test_self_find_files_with_gemfile to sort expected files. Pull
    request #1880 by Kazuaki Matsuo.
  • Fix issue for MinGW / MSYS2 builds and testing. Pull request #1879 by
    MSP-Greg.
  • Fix gem open to open highest version number rather than lowest. Pull
    request #1877 by Tim Pope.
  • Add a test for requiring a default spec as installed by the ruby
    installer. Pull request #1899 by Samuel Giddins.
  • Fix broken --exact parameter to gem command. Pull request #1873 by Jason
    Frey.
  • [Installer] Generate backwards-compatible binstubs. Pull request #1904
    by Samuel Giddins.
  • Fix pre-existing source recognition on add action. Pull request #1883 by
    Jonathan Claudius.
  • Prevent negative IDs in output of #inspect. Pull request #1908 by Vít
    Ondruch.
  • Allow Gem.finish_resolve to respect already-activated specs. Pull
    request #1910 by Samuel Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.11

Bug fixes:

  • Fixed broken tests on ruby-head. Pull request #1841 by
    SHIBATA Hiroshi.
  • Update vendored Molinillo to 0.5.7. Pull request #1859 by Samuel
    Giddins.
  • Avoid activating Ruby 2.5 default gems when possible. Pull request #1843
    by Samuel Giddins.
  • Use improved resolver sorting algorithm. Pull request #1856 by
    Samuel Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.10

Bug fixes:

  • Fix require calling the wrong gem method when it is overridden.
    Pull request #1822 by Samuel Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.9

Bug fixes:

  • Allow initializing versions with empty strings. Pull request #1767 by
    Luis Sagastume.
  • Fix TypeError on 2.4. Pull request #1788 by Nobuyoshi Nakada.
  • Don't output mkmf.log message if compilation didn't fail. Pull request
    #1808 by Jeremy Evans.
  • Fixed broken links and overzealous URL encoding in gem server. Pull
    request #1809 by Nicole Orchard.
  • Update vendored Molinillo to 0.5.5. Pull request #1812 by Samuel
    Giddins.
  • RakeBuilder: avoid frozen string issue. Pull request #1819 by Olle
    Jonsson.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.8

Bug fixes:

  • Improve SSL verification failure message. Pull request #1751
    by Eric Hodel.
  • Ensure to_spec falls back on prerelease specs. Pull request
    #1755 by André Arko.
  • Update vendored Molinillo to 0.5.3. Pull request #1763 by
    Samuel Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.7

Bug fixes:

  • Install native extensions in the correct location when using the
    --user-install flag. Pull request #1683 by Noah Kantrowitz.
  • When calling Gem.sources, load sources from configuration
    if present, else use the default sources. Pull request #1699
    by Luis Sagastume.
  • Fail gracefully when attempting to redirect without a Location.
    Pull request #1711 by Samuel Giddins.
  • Update vendored Molinillo to 0.5.1. Pull request #1714 by
    Samuel Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.6

Bug fixes:

  • Sort installed versions to make sure we install the latest version when
    running gem update --system. As a one-time fix, run
    gem update --system=2.6.6. Pull request #1601 by David Radcliffe.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.5

Enhancements:

  • Support for unified Integer in Ruby 2.4. Pull request #1618
    by SHIBATA Hiroshi.
  • Update vendored Molinillo to 0.5.0 for performance improvements.
    Pull request #1638 by Samuel Giddins.

Bug fixes:

  • Raise an explicit error if Signer#sign is called with no certs. Pull
    request #1605 by Daniel Berger.
  • Update update_bundled_ca_certificates utility script for directory
    nesting. Pull request #1583 by James Wen.
  • Fix broken symlink support in tar writer (+ fix broken test). Pull
    request #1578 by Cezary Baginski.
  • Remove extension directory before (re-)installing. Pull request #1576
    by Jeremy Hinegardner.
  • Regenerate test CA certificates with appropriate extensions. Pull
    request #1611 by rhenium.
  • Rubygems does not terminate on failed file lock when not superuser. Pull
    request #1582 by Ellen Marie Dash.
  • Fix tar headers with a 101 character name. Pull request #1612 by Paweł
    Tomulik.
  • Add Gem.platform_defaults to allow implementations to override defaults.
    Pull request #1644 by Charles Oliver Nutter.
  • Run Bundler tests on TravisCI. Pull request #1650 by Samuel Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.4

Enhancements:

  • Use Gem::Util::NULL_DEVICE instead of hard coded strings. Pull request #1588
    by Chris Charabaruk.
  • Use File.symlink on MS Windows if supported. Pull request #1418
    by Nobuyoshi Nakada.

Bug fixes:

  • Redact uri password from error output when gem fetch fails. Pull request
    #1565 by Brian Fletcher.
  • Suppress warnings. Pull request #1594 by Nobuyoshi Nakada.
  • Escape user-supplied content served on web pages by gem server to avoid
    potential XSS vulnerabilities. Samuel Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.3

Enhancements:

  • Lazily calculate Gem::LoadError exception messages. Pull request #1550
    by Aaron Patterson.
  • New fastly cert. Pull request #1548 by David Radcliffe.
  • Organize and cleanup SSL certs. Pull request #1555 by James Wen.
  • [RubyGems] Make deprecation message for paths= more helpful. Pull
    request #1562 by Samuel Giddins.
  • Show default gems when using "gem list". Pull request #1570 by Luis
    Sagastume.

Bug fixes:

  • Stub ordering should be consistent regardless of how cache is populated.
    Pull request #1552 by Aaron Patterson.
  • Handle cases when the @@stubs variable contains non-stubs. Pull request
    #1558 by Per Lundberg.
  • Fix test on Windows for inconsistent temp path. Pull request #1554 by
    Hiroshi Shirosaki.
  • Fix Gem.find_spec_for_exe picks oldest gem. Pull request #1566 by
    Shinichi Maeshima.
  • [Owner] Fallback to email and userid when owner email is missing. Pull
    request #1569 by Samuel Giddins.
  • [Installer] Handle nil existing executable. Pull request #1561 by Samuel
    Giddins.
  • Allow two digit version numbers in the tests. Pull request #1575 by unak.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.2

Bug fixes:

  • Fix wrong version of gem activation for bin stub. Pull request #1527 by
    Aaron Patterson.
  • Speed up gem activation failures. Pull request #1539 by Aaron Patterson.
  • Fix platform sorting in the resolver. Pull request #1542 by Samuel E.
    Giddins.
  • Ensure we unlock the monitor even if try_activate throws. Pull request
    #1538 by Charles Oliver Nutter.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.6.1

Bug fixes:

  • Ensure default_path and home are set for paths. Pull request #1513
    by Aaron Patterson.
  • Restore but deprecate support for Array values on Gem.paths=. Pull
    request #1514 by Aaron Patterson.
  • Fix invalid gem file preventing gem install from working. Pull request
    #1499 by Luis Sagastume.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.5.2

Bug fixes:

  • Fix memoization of Gem::Version#prerelease? Pull request #1125 by Matijs van
    Zuijlen.
  • Handle trailing colons in GEM_PATH, by Damien Robert.
  • Improve the Gemfile gemspec method, fixing #1204 and #1033. Pull request
    #1276 by Michael Papis.
  • Warn only once when a gemspec license is invalid. Pull request #1414 by Samuel
    E. Giddins.
  • Check for exact constants before using them, fixing Ruby bug #11940. Pull
    request #1438 by Nobuyoshi Nakada.
  • Fix building C extensions on Ruby 1.9.x on Windows. Pull request #1453 by Marie
    Markwell.
  • Handle symlinks containing ".." correctly. Pull request #1457 by Samuel E.
    Giddins.

Enhancements:

  • Add --no-rc flag, which skips loading .gemrc. Pull request #1329 by Luis
    Sagastume.
  • Allow basic auth to be excluded from allowed_push_host. By Josh Lane.
  • Add gem list --exact, which finds gems by string match instead of regex. Pull
    request #1344 by Luis Sagastume.
  • Suggest alternatives when gem license is unknown. Pull request #1443 by Samuel
    E. Giddins.
  • Print a useful error if a binstub expects a newer version of a gem than is
    installed. Pull request #1407 by Samuel E. Giddins.
  • Allow the (supported) s3:// scheme to be used with --source. Pull request
    #1416 by Dave Adams.
  • Add --[no-]post-install-message to install and update. Pull request #1162
    by Josef Šimánek.
  • Add --host option to yank, providing symmetry with pull. Pull request
    #1361 by Mike Virata-Stone.
  • Update bundled Molinillo to 0.4.1. Pull request #1452 by Samuel E. Giddins.
  • Allow calling build without '.gemspec'. Pull request #1454 by Stephen
    Blackstone.
  • Add support for source option on gems in Gemfile. Pull request #1355 by
    Michael Papis.
  • Function correctly when string literals are frozen on Ruby 2.3. Pull request
    #1408 by Samuel E. Giddins.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.5.1

Bug fixes:

  • Ensure platform sorting only uses strings. Affected binary installs on Windows.
    Issue #1369 reported by Ryan Atball (among others).
    Pull request #1375 by Samuel E. Giddins.
  • Revert PR #1332. Unable to reproduce, and nil should be impossible.
  • Gem::Specification#to_fullpath now returns .rb extensions when such a file
    exists. Pull request #1114 by y-yagi.
  • RubyGems now handles Net::HTTPFatalError instead of crashing. Pull
    request #1314 by Samuel E. Giddins.
  • Updated bundled Molinillo to 0.4.0. Pull request #1322, #1396 by Samuel E.
    Giddins.
  • Improved performance of spec loading by reducing likelihood of loading the
    complete specification. Pull request #1373 by Aaron Patterson.
  • Improved caching of requirable files Pull request #1377 by Aaron Patterson.
  • Fixed activation of gems with development dependencies. Pull request #1388
    by Samuel E. Giddins.
  • RubyGems now uses the same Molinillo vendoring strategy as Bundler. Pull
    request #1397 by Samuel E. Giddins.
  • Fixed documentation of Gem::Requirement.parse. Pull request #1398 by
    Juanito Fatas.
  • RubyGems no longer warns when a prerelease gem has prerelease dependencies.
    Pull request #1399 by Samuel E. Giddins.
  • Fixed Gem::Version documentation example. Pull request #1401 by Guilherme
    Goettems Schneider.
  • Updated documentation links to https://. Pull request #1404 by Suriyaa
    Kudo.
  • Fixed double word typo. Pull request #1411 by Jake Worth.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.5.0

Enhancements:

  • Added the Gem::Licenses class which provides a set of standard license
    identifiers as set by spdx.org. This is now used by the
    Gem::Specification#license attribute to try to standardize (though not
    enforce) licenses set by gem authors.

    Pull request #1249 by Kyle Mitchell.

  • Use Molinillo as the resolver library. This is the same resolver as used by
    Bundler. Pull request #1189 by Samuel E. Giddins.

  • Add --skip=gem_name to Pristine command. Pull request #1018 by windwiny.

  • The parsed gem dependencies file is now available via Gem.gemdeps following
    Gem.use_gemdeps. Pull request #1224 by Hsing-Hui Hsu, issue #1213 by
    Michal Papis.

  • Moved description attribute to recommended for Gem::Specification.
    Pull request #1046 by Michal Papis

  • Moved Gem::Indexer#abbreviate and #sanitize to Gem::Specification.
    Pull request #1145 by Arthur Nogueira Neves

  • Cache Gem::Version segments for #bump and #release.
    Pull request #1131 by Matijs van Zuijlen

  • Fix edge case in levenshtein_distance for comparing longer strings.
    Pull request #1173 by Richard Schneeman

  • Remove duplication from List#to_a, improving from O(n^2) to O(n) time.
    Pull request #1200 by Marc Siegel.

  • Gem::Specification.add_specs is deprecated and will be removed from version
    3.0 with no replacement. To add specs, install the gem, then reset the
    cache.

  • Gem::Specification.add_spec is deprecated and will be removed from version
    3.0 with no replacement. To add specs, install the gem, then reset the
    cache.

  • Gem::Specification.remove_spec is deprecated and will be removed from version
    3.0 with no replacement. To remove specs, uninstall the gem, then reset the
    cache by calling Gem::Specification.reset.

  • Call Array#compact before calling Array#uniq for minor speed improvement in
    the Gem::Specification#files method.
    Pull request #1253 by Marat Amerov.

  • Use stringio instead of custom String classes.
    Pull request #1250 by Petr Skocik.

  • Use URI#host instead of URI#hostname to retain backwards compatibility with
    Ruby 1.9.2 and earlier in util library.
    Pull request #1288 by Joe Rafaniello.

  • Documentation update for gem sources.
    Pull request #1324 by Ilya Vassilevsky.

  • Documentation update for required_ruby_version.
    Pull request #1321 by Matt Patterson.

  • Documentation update for gem update.
    Pull request #1306 by Tim Blair.

  • Emit a warning on SRV resolve failure.
    Pull request #1023 by Ivan Kuchin.

  • Allow duplicate dependencies between runtime and development.
    Pull request #1032 by Murray Steele.

  • The gem env command now shows the user installation directory.
    Pull request #1343 by Luis Sagastume.

  • The Gem::Platform#=== method now treats a nil cpu arch the same as 'universal'.
    Pull request #1356 by Daniel Berger.

  • Improved memory performance in Gem::Specification.traverse. Pull request
    #1188 by Aaron Patterson.

  • RubyGems packages now support symlinks. Pull request #1209 by Samuel E.
    Giddins.

  • RubyGems no longer outputs mkmf.log if it does not exist. Pull request
    #1222 by Andrew Hooker.

  • Added Bitrig platform. Pull request #1233 by John C. Vernaleo.

  • Improved error message for first-time RubyGems developers. Pull request
    #1241 by André Arko

  • Improved performance of Gem::Specification#load with cached specs. Pull
    request #1297 by Samuel E. Giddins.

  • Gem::RemoteFetcher allows users to set HTTP headers. Pull request #1363 by
    Agis Anastasopoulos.

Bug fixes:

  • Fixed Rake homepage url in example for Gem::Specification#homepage.
    Pull request #1171 by Arthur Nogueira Neves
  • Don't crash if partially uninstalled gem can't be found.
    Pull request #1283 by Cezary Baginski.
  • Test warning cleanup.
    Pull request #1298 by Samuel E. Giddins.
  • Documentation fix for GemDependencyAPI.
    Pull request #1308 by Michael Papis.
  • Fetcher now ignores ENOLCK errors in single threaded environments. This
    handles an issue with gem installation on NFS as best we can. Addresses
    issue #1176 by Ryan Moore.
    Pull request #1327 by Daniel Berger.
  • Fix some path quoting issues in the test suite.
    Pull request #1328 by Gavin Miller.
  • Fix NoMethodError in running ruby processes when gems are uninstalled.
    Pull request #1332 by Peter Drake.
  • Fixed a potential NoMethodError for gem cleanup.
    Pull request #1333 by Peter Drake.
  • Fixed gem help bug.
    Issue #1352 reported by bogem, pull request #1357 by Luis Sagastume.
  • Remove temporary directories after tests finish. Pull request #1181 by
    Nobuyoshi Nokada.
  • Update links in RubyGems documentation. Pull request #1185 by Darío Hereñú.
  • Prerelease gem executables can now be run. Pull request #1186 by Samuel E.
    Giddins.
  • Updated RubyGems travis-ci ruby versions. Pull request #1187 by Samuel E.
    Giddins.
  • Fixed release date of RubyGems 2.4.6. Pull request #1190 by Frieder
    Bluemle.
  • Fixed bugs in gem activation. Pull request #1202 by Miklós Fazekas.
  • Fixed documentation for gem list. Pull request #1228 by Godfrey Chan.
  • Fixed #1200 history entry. Pull request #1234 by Marc Siegel.
  • Fixed synchronization issue when resetting the Gem::Specification gem list.
    Pull request #1239 by Samuel E. Giddins.
  • Fixed running tests in parallel. Pull request #1257 by SHIBATA Hiroshi.
  • Fixed running tests with --program-prefix or --program-suffix for ruby.
    Pull request #1258 by Shane Gibbs.
  • Fixed Gem::Specification#to_yaml. Pull request #1262 by Hiroaki Izu.
  • Fixed taintedness of Gem::Specification#raw_require_paths. Pull request
    #1268 by Sam Ruby.
  • Fixed sorting of platforms when installing gems. Pull request #1271 by
    nonsequitur.
  • Use --no-document over deprecated documentation options when installing
    dependencies on travis. Pull request #1272 by takiy33.
  • Improved support for IPv6 addresses in URIs. Pull request #1275 by Joe
    Rafaniello.
  • Spec validation no longer crashes if a file does not exist. Pull request
    #1278 by Samuel E. Giddins.
  • Gems can now be installed within rescue. Pull request #1282 by Samuel E.
    Giddins.
  • Increased Diffie-Hellman key size for tests for modern OpenSSL. Pull
    request #1290 by Vít Ondruch.
  • RubyGems handles invalid config files better. Pull request #1367 by Agis
    Anastasopoulos.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.4.8

Bug fixes:

  • Tightened API endpoint checks for CVE-2015-3900

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.4.7

Bug fixes:

  • Limit API endpoint to original security domain for CVE-2015-3900.
    Fix by claudijd

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.4.6

Bug fixes:

  • Fixed resolving gems with both upper and lower requirement boundaries.
    Issue #1141 by Jakub Jirutka.
  • Moved extension directory after require_paths to fix missing constant bugs
    in some gems with C extensions. Issue #784 by André Arko, pull request
    #1137 by Barry Allard.
  • Use Gem::Dependency#requirement when adding a dependency to an existing
    dependency instance. Pull request #1101 by Josh Cheek.
  • Fixed warning of shadowed local variable in Gem::Specification. Pull request
    #1109 by Rohit Arondekar
  • Gem::Requirement should always sort requirements before coercion to Hash.
    Pull request #1139 by Eito Katagiri.
  • The gem open command should change the current working directory before
    opening the editor. Pull request #1142 by Alex Wood.
  • Ensure quotes are stripped from the Windows launcher script used to install
    gems. Pull request #1115 by Youngjun Song.
  • Fixed errors when writing to NFS to to 0444 files. Issue #1161 by Emmanuel
    Hadoux.
  • Removed dead code in Gem::StreamUI. Pull request #1117 by mediaslave24.
  • Fixed typos. Pull request #1096 by hakeda.
  • Relaxed CMake dependency for RHEL 6 and CentOS 6. Pull request #1124 by Vít
    Ondruch.
  • Relaxed Psych dependency. Pull request #1128 by Vít Ondruch.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.4.5

Bug fixes:

  • Improved speed of requiring gems. (Around 25% for a 60 gem test). Pull
    request #1060 by unak.
  • RubyGems no longer attempts to look up gems remotely with the --local flag.
    Pull request #1084 by Jeremy Evans.
  • Executable stubs use the correct gem version when RUBYGEMS_GEMDEPS is
    active. Issue #1072 by Michael Kaiser-Nyman.
  • Fixed handling of pinned gems in lockfiles with versions. Issue #1078 by
    Ian Ker-Seymer.
  • Fixed handling of git@example:gem.git URIs. Issue #1054 by Mogutan Mogu.
  • Fixed handling of platforms retrieved from the dependencies API. Issue
    #1058 and patch suggestion by tux-mind.
  • RubyGems now suggests a copy-pasteable gem pristine command when
    extensions are missing. Pull request #1057 by Shannon Skipper.
  • Improved errors for long file names when packaging. Pull request #1016 by
    Piotrek Bator.
  • gem pristine now skips gems cannot be found remotely. Pull request #1064
    by Tuomas Kareinen.
  • gem pristine now caches gems to the proper directory. Pull request #1064
    by Tuomas Kareinen.
  • gem pristine now skips bundled gems properly. Pull request #1064 by
    Tuomas Kareinen.
  • Improved interoperability of Vagrant with RubyGems. Pull request #1057 by
    Vít Ondruch.
  • Renamed CONTRIBUTING to CONTRIBUTING.rdoc to allow markup. Pull request
    #1090 by Roberto Miranda.
  • Switched from #partition to #reject as only one collection is used. Pull
    request #1074 by Tuomas Kareinen.
  • Fixed installation of gems on systems using memory-mapped files. Pull
    request #1038 by Justin Li.
  • Fixed bug in Gem::Text#min3 where a == b < c. Pull request #1026 by
    fortissimo1997.
  • Fixed uninitialized variable warning in BasicSpecification. Pull request
    #1019 by Piotr Szotkowski.
  • Removed unneeded exception handling for cyclic dependencies. Pull request
    #1043 by Jens Wille.
  • Fixed grouped expression warning. Pull request #1081 by André Arko.
  • Fixed handling of platforms when writing lockfiles.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.4.4

Bug fixes:

  • Add alternate Root CA for upcoming certificate change. Fixes #1050 by
    Protosac

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.4.3

Bug fixes:

  • Fix redefine MirrorCommand issue. Pull request #1044 by @akr.
  • Fix typo in platform= docs. Pull request #1048 by @jasonrclark
  • Add root SSL certificates for upcoming certificate change. Fixes #1050 by
    Protosac

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.4.2

This release was sponsored by Ruby Central.

Bug fixes:

  • RubyGems now correctly matches wildcard no_proxy hosts. Issue #997 by
    voelzemo.
  • Added support for missing git_source method in the gem dependencies API.
  • Fixed handling of git gems with an alternate install directory.
  • Lockfiles will no longer be truncated upon resolution errors.
  • Fixed messaging for gem owner -a. Issue #1004 by Aaron Patterson, Ryan
    Davis.
  • Removed meaningless ensure. Pull request #1003 by gogotanaka.
  • Improved wording of --source option help. Pull request #989 by Jason Clark.
  • Empty build_info files are now ignored. Issue #903 by Adan Alvarado.
  • Gem::Installer ignores dependency checks when installing development
    dependencies. Issue #994 by Jens Willie.
  • gem update now continues after dependency errors. Issue #993 by aaronchi.
  • RubyGems no longer warns about semantic version dependencies for the 0.x
    range. Issue #987 by Jeff Felchner, pull request #1006 by Hsing-Hui Hsu.
  • Added minimal lock to allow multithread installation of gems. Issue #982
    and pull request #1005 by Yorick Peterse
  • RubyGems now considers prerelease dependencies as it did in earlier versions
    when --prerelease is given. Issue #990 by Jeremy Tryba.
  • Updated capitalization in README. Issue #1010 by Ben Bodenmiller.
  • Fixed activating gems from a Gemfile for default gems. Issue #991 by khoan.
  • Fixed windows stub script generation for Cygwin. Issue #1000 by Brett
    DiFrischia.
  • Allow gem bindir and ruby.exe to live in separate directories. Pull request
    #942 by Ian Flynn.
  • Fixed handling of gemspec in gem dependencies files to match Bundler
    behavior. Issue #1020 by Michal Papis.
  • Fixed gem update when updating to prereleases. Issue #1028 by Santiago
    Pastorino.
  • RubyGems now fails immediately when a git reference cannot be found instead
    of spewing git errors. Issue #1031 by Michal Papis

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.4.1

Bug fixes:

  • RubyGems can now be updated on Ruby implementations that do not support
    vendordir in RbConfig::CONFIG. Issue #974 by net1957.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.4.0

Enhancements:

  • The contents command now supports a --show-install-dir option that shows
    only the directory the gem is installed in. Feature request #966 by Akinori
    MUSHA.
  • Added a --build-root option to the install command for packagers. Pull
    request #965 by Marcus Rückert.
  • Added vendor gem support to RubyGems. Package managers may now install gems
    in Gem.vendor_dir with the --vendor option to gem install. Issue #943 by
    Marcus Rückert.

Bug fixes:

  • Kernel#gem now respects the prerelease flag when activating gems.
    Previously this behavior was undefined which could lead to bugs when a
    prerelease version was unintentionally activated. Bug #938 by Joe Ferris.
  • RubyGems now prefers gems from git over installed gems. This allows gems
    from git to override an installed gem with the same name and version. Bug
    #944 by Thomas Kriechbaumer.
  • Fixed handling of git gems in a lockfile with unversioned dependencies. Bug
    #940 by Michael Kaiser-Nyman.
  • The ruby directive in a gem dependencies file is ignored when installing.
    Bug #941 by Michael Kaiser-Nyman.
  • Added open to list of builtin commands (gem open now works). Reported by
    Espen Antonsen.
  • gem open now works with command-line editors. Pull request #962 by Tim
    Pope.
  • gem install -g now respects --conservative. Pull request #950 by Jeremy
    Evans.
  • RubyGems releases announcements now now include checksums. Bug #939 by
    Alexander E. Fischer.
  • RubyGems now expands ~ in $PATH when checking if installed executables will
    be runnable. Pull request #945 by Alex Talker.
  • Fixed gem install -g --explain. Issue #947 by Luis Lavena. Patch by
    Hsing-Hui Hsu.
  • RubyGems locks less during gem activation. Pull request #951 by Aaron
    Patterson and Justin Searls, #969 by Jeremy Tryba.
  • Kernel#gem is now thread-safe. Pull request #967 by Aaron Patterson.
  • RubyGems now handles spaces in directory names for some parts of extension
    building. Pull request #949 by Tristan Hill.
  • RubyGems no longer defines an empty Date class. Pull Request #948 by Benoit
    Daloze.
  • RubyGems respects --document options for gem update again. Bug 946 by
    jonforums. Patch by Hsing-Hui Hsu.
  • RubyGems generates documentation again with --ignore-dependencies. Bug #961
    by Pulfer.
  • RubyGems can install extensions across partitions now. Pull request #970 by
    Michael Scherer.
  • -s is now short for --source which resolves an ambiguity with
    --no-suggestions. Pull request #955 by Alexander Kahn.
  • Added extra test for ~> for 0.0.X versions. Pull request #958 by Mark
    Lorenz.
  • Fixed typo in gem updated help. Pull request #952 by Per Modin.
  • Clarified that the gem description should not be excessively long. Part of
    bug #956 by Renier Morales.
  • Hid documentation of outdated test_files related methods in Specification.
    Guides issue #90 by Emil Soman.
  • RubyGems now falls back to the old index if the rubygems.org API fails
    during gem resolution.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.3.0

Enhancements:

  • Added the open command which allows you to inspect the source of a gem
    using your editor.
    Issue #789 by Mike Perham. Pull request #804 by Vitali F.
  • The update command shows a summary of which gems were and were not
    updated. Issue #544 by Mark D. Blackwell.
    Pull request #777 by Tejas Bubane.
  • Improved "could not find 'gem'" error reporting. Pull request #913 by
    Richard Schneeman.
  • Gem.use_gemdeps now accepts an argument specifying the path of the gem
    dependencies file. When the file is not found an ArgumentError is raised.
  • Writing a .lock file for a gem dependencies file is now controlled by the
    --[no-]lock option. Pull request #774 by Jeremy Evans.
  • Suggestion of alternate names and spelling corrections during install can be
    suppressed with the --no-suggestions option. Issue #867 by Jimmy Cuadra.
  • Added mswin64 support. Pull request #881 by U. Nakamura.
  • A gem is installable from an IO again (as in RubyGems 1.8.x and older).
    Pull request #716 by Xavier Shay.
  • RubyGems no longer attempts to build extensions during activation. Instead
    a warning is issued instructing you to run gem pristine which will build
    the extensions for the current platform. Issue #796 by dunric.
  • Added Gem::UserInteraction#verbose which prints when the --verbose option is
    given. Pull request #811 by Aaron Patterson.
  • RubyGems can now fetch gems from private repositories using S3. Pull
    request #856 by Brian Palmer.
  • Added Gem::ConflictError subclass of Gem::LoadError so you can distinguish
    conflicts from other problems. Pull request #841 by Aaron Patterson.
  • Cleaned up unneeded load_yaml bootstrapping in Rakefile. Pull request #815
    by Zachary Scott.
  • Improved performance of conflict resolution. Pull request #842 by Aaron
    Patterson.
  • Add documentation of "~> 0" to Gem::Version. Issue #896 by Aaron Suggs.
  • Added CONTRIBUTING file. Pull request #849 by Mark Turner.
  • Allow use of bindir in windows_stub_script in .bat
    Pull request #818 by @unak and @nobu
  • Use native File::PATH_SEPARATOR and remove $ before gem env on
    Gem::Dependency#to_specs. Pull request #915 by @parkr
  • RubyGems recommends SPDX IDs for licenses now. Pull request #917 by
    Benjamin Fleischer.

Bug fixes:

  • RubyGems now only fetches the latest specs to find misspellings which speeds
    up gem suggestions. Pull request #808 by Aaron Patterson.
  • The given .gem is installed again when multiple versions of the same gem
    exist in the current directory. Bug #875 by Prem Sichanugrist.
  • Local gems are preferred by name over remote gems again. Bug #834 by
    jonforums.
  • RubyGems can install local prerelease gems again. Pull request #866 by
    Aaron Patterson. Issue #813 by André Arko.
  • RubyGems installs development dependencies correctly again. Issue #893 by
    Jens Wille.
  • RubyGems only installs prerelease versions when they are requested again.
    Issue #853 by Seth Vargo, special thanks to Zachary Scott and Ben Moss.
    Issue #884 by Nathaniel Bibler.
  • Fixed RubyGems list and search command help. Pull request #905 and #928 by
    Gabriel Gilder.
  • The list of gems to uninstall is always sorted now. Bug #918 by postmodern.
  • The update command only updates exactly matching gem names now. Bug #919 by
    postmodern.
  • Gem::Server now supports prerelease versions. Bug #857 by Marcelo Alvim.
  • RubyGems no longer raises an exception immediately when gems are missing
    with RUBYGEMS_GEMDEPS. A warning is printed instead. Issue #886 by Michael
    Kaiser-Nyman.
  • Commands using the rubygems.org API no longer try to sign-in when a
    non-rubygems API key has been chosen. Bug #826 by Ben Sedat.
  • Updated documentation of Gem::Specification#executables to indicate that
    only ruby scripts are allowed. Bug #830 by Geoff Nixon.
  • Gem dependency API supports multiple platforms for #platform and #platforms
    now. Bug #821 by johnny5-.
  • Gem dependency API supports lockfiles without explicit sources. Bug #820 by
    johnny5-.
  • Gem dependency API supports lockfiles with multiple sources. Bug #822 by
    johnny5-, bug #851 by sumit shah.
  • Gem dependency API supports lockfiles with git sources using branch, tag and
    ref. Bug #822 by johnny5-, #931 by Christoph Blank.
  • Gem dependency API no longer raises an exception when a gem does not exist
    in one of the configured sources. Bug #897 by Michael Kaiser-Nyman.
  • Gem dependency API no longer lists development dependencies in the lockfile.
    Bug #768 by Diego Viola, #916 by Santiago Pastorino.
  • SSL configuration entries in ~/.gemrc are properly round-tripped. Bug #837
    by Noah Luck Easterly.
  • The environment command now shows the system configuration directory where
    the all-users gemrc lives. Bug #827 by Ben Langfeld.
  • Improved speed of conflict checking when activating gems. Pull request #843
    by Aaron Patterson.
  • Improved speed of levenshtein distance for gem suggestion misspellings.
    Pull requests #809, #812 by Aaron Patterson.
  • Restored persistent connections. Pull request #869 by Aaron Patterson.
  • Reduced requests when fetching gems with the bundler API. Pull request #773
    by Charlie Somerville.
  • Reduced dependency prefetching to improve install speed. Pull requests
    #871, #872 by Matthew Draper.
  • RubyGems now avoids net/http auto-proxy detection. Issue #824 by HINOHARA
    Hiroshi.
  • Removed conversion of Gem::List (used for debugging installs) to unless
    necessary. Pull request #870 by Aaron Patterson.
  • RubyGems now prints release notes from the current release. Bug #814 by
    André Arko.
  • RubyGems allows installation of unsigned gems again with -P MediumSecurity
    and lower. Bug #859 by Justin S. Collins.
  • Fixed typo in Jim Weirich's name. Ruby pull request #577 by Mo Khan.
  • Fixed typo in Gem.datadir documentation. Pull request #868 by Patrick
    Jones.
  • Fixed File.exists? warnings. Pull request #829 by SHIBATA Hiroshi.
  • Fixed show_release_notes test for LANG=C. Issue #862 by Luis Lavena.
  • Fixed Gem::Package from IO tests on windows. Patch from issue #861 by Luis
    Lavena.
  • Check for nil extensions as BasicSpecification does not initialize them.
    Pull request #882 by André Arko.
  • Fixed Gem::BasicSpecification#require_paths receives a String for
    @require_paths. Pull request #904 by @danielpclark
  • Fixed circular require warnings. Bug #908 by Zachary Scott.
  • Gem::Specification#require_paths can no longer accidentally be an Array.
    Pull requests #904, #909 by Daniel P. Clark.
  • Don't build extensions if build_dir/extensions isn't writable.
    Pull request #912 by @dunric
  • Gem::BasicSpecification#require_paths respects default_ext_dir_for now. Bug
    #852 by Vít Ondruch.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.2.5

Bug fixes:

  • Tightened API endpoint checks for CVE-2015-3900

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.2.4

Bug fixes:

  • Backport: Limit API endpoint to original security domain for CVE-2015-3900.
    Fix by claudijd

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.2.2

Bug fixes:

  • Fixed ruby tests when BASERUBY is not set. Patch for #778 by Nobuyoshi
    Nakada.
  • Removed double requests in RemoteFetcher#cache_update_path to improve remote
    install speed. Pull request #772 by Charlie Somerville.
  • The mkmf.log is now placed next to gem_make.out when building extensions.
  • gem install -g --local no longer accesses the network. Bug #776 by Jeremy
    Evans.
  • RubyGems now correctly handles URL passwords with encoded characters. Pull
    request #781 by Brian Fletcher.
  • RubyGems now correctly escapes URL characters. Pull request #788 by Brian
    Fletcher.
  • RubyGems can now unpack tar files where the type flag is not given. Pull
    request #790 by Cody Russell.
  • Typo corrections. Pull request ruby/ruby#506 by windwiny.
  • RubyGems now uses both the default certificates and ssl_ca_cert instead of
    one or the other. Pull request #795 by zebardy.
  • RubyGems can now use the bundler API against hosted gem servers in a
    directory. Pull request #801 by Brian Fletcher.
  • RubyGems bin stubs now ignore non-versions. This allows RubyGems bin stubs
    to list file names like "foo". Issue #799 by Postmodern.
  • Restored behavior of Gem::Version::new when subclassed. Issue #805 by
    Sergio Rubio.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.2.1

Bug fixes:

  • Platforms in the Gemfile.lock GEM section are now handled correctly. Bug
    #767 by Diego Viola.
  • RubyGems now displays which gem couldn't be uninstalled from the home
    directory. Pull request #757 by Michal Papis.
  • Removed unused method Gem::Resolver#find_conflict_state. Pull request #759
    by Smit Shah.
  • Fixed installing gems from local files without dependencies. Issue #760 by
    Arash Mousavi, pull request #764 by Tim Moore.
  • Removed TODO about syntax that works in Ruby 1.8.7. Pull request #765 by
    Benjamin Fleischer.
  • Switched Gem.ruby_api_version to use RbConfig::CONFIG['ruby_version'] which
    has the same value but is overridable by packagers through
    --with-ruby-version= when configuring ruby. Bug #770 by Jeremy Evans.
  • RubyGems now prefers the bundler API for gem install to reduce HTTP
    requests. (This change was intended for RubyGems 2.2.0 but was missed.)
    This should address bug #762 by Dan Peterson and bug #766 by mipearson.
  • Added Gem::BasicSpecification#source_paths so documentation or analysis
    tools can work properly as require_paths no longer returns extension source
    directories. Bug #758 Vít Ondruch.
  • Gem.read_binary can read read-only files again. This caused file://
    repositories to stop working. Bug #761 by John Anderson.
  • Fixed specification file sorting for Ruby 1.8.7 compatibility. Pull
    request #763 by James Mead

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.2.0

Special thanks to Vít Ondruch and Michal Papis for testing and finding bugs in
RubyGems as it was prepared for the 2.2.0 release.

Enhancements:

  • RubyGems can check for gem dependencies files (gem.deps.rb or Gemfile) when
    rubygems executables are started and uses the found dependencies. This
    means rake will work similar to bundle exec rake. To enable this set
    the RUBYGEMS_GEMDEPS environment variable to the location of your
    dependencies file.

    See Gem::use_gemdeps for further details.

  • A RubyGems directory may now be shared amongst multiple ruby versions. Upon
    activation RubyGems will automatically compile missing extensions for the
    current platform when the built objects are missing. Issue #596 by Michal
    Papis

    By default different platforms do not share gem install locations so this
    must be configured by setting GEM_HOME to a common directory. Some gems use
    fixed paths for requiring extensions and are not compatible with sharing gem
    directories.

    The default sharing location may be configured by RubyGems packagers through
    Gem.default_ext_dir_for. Pull Request #744 by Vít Ondruch.

  • RubyGems checks the 'allowed_push_host' metadata value when pushing a gem to
    prevent an accidental push to a public repository (such as rubygems.org).
    If you have private gems you should set this value in your gem specification
    metadata. Pull request #603 by Seamus Abshere.

  • gem list now shows results for multiple arguments. Pull request #604 by
    Zach Rabinovich.

  • gem pristine --extensions will restore only gems with extensions. Issue
    #619 by Postmodern.

  • Gem::Specification#files is now sorted. Pull request #612 by Justin George.

  • For gem list and friends, "LOCAL" and "REMOTE" headers are omitted if
    only local or remote gem information is requested with --quiet. Pull
    request #615 by Michal Papis.

  • Added Gem::Specification#full_require_paths which is like require_paths, but
    returns a fully-qualified results. Pull request #632 by Vít Ondruch.

  • RubyGems now looks for the https_proxy environment variable for https://
    sources. RubyGems will fall back to http_proxy if there is no https_proxy.
    Issue #610 by mkristian.

  • RubyGems now creates directories in .gem files. Issue #631 by marksolaris.

  • RubyGems raises an exception when a specification includes its gem. Issue
    #623 by notEthan.

  • RubyGems now displays relevant release note information when updating
    RubyGems. Issue #647 by Trevor Wennblom.

  • Deprecated Gem::Installer::ExtensionBuildError in favor of
    Gem::Ext::BuildError. The old constant is an alias for the new constant.

  • When extensions are built the gem_make.out file is always written now, even
    on success. This will help with debugging bad builds that report success.

  • If a specification fails to validate RubyGems shows a link to the
    specification reference guide. Issue #656 by Markus Heiler.

  • When using gem install -g, RubyGems now detects the presence of an
    Isolate, Gemfile or gem.deps.rb file.

  • Added Gem::StubSpecification#stubbed? to help determine if a user should run
    gem pristine to speed up gem loading. Pull request #694 and #701 by Jon
    Leighton.

  • RubyGems now warns when a gem has a pessimistic version dependency that may
    be too strict.

  • RubyGems now warns when a gem has an open-ended dependency.

  • RubyGems now raises an exception when a dependency for a gem is defined
    twice.

  • Marked the license specification attribute as recommended. Pull request
    #713 by Benjamin Fleischer.

  • RubyGems uses io/console instead of stty when available. Pull request
    #740 by Nobuyoshi Nakada

  • Relaxed Gem.ruby tests for platforms that override where ruby lives. Pull
    Request #755 by strzibny.

Bug fixes:

  • RubyGems now returns an error status when any file given to gem which
    cannot be found. Ruby bug #9004 by Eugene Vilensky.
  • Fixed command escaping when building rake extensions. Pull request #721 by
    Dmitry Ratnikov.
  • Fixed uninstallation of gems when GEM_HOME is a relative directory. Issue
    #708 by Ryan Davis.
  • Default gems are now ignored by Gem::Validator#alien. Issue #717 by David
    Bahar.
  • Fixed typos in RubyGems. Pull requests #723, #725, #731 by Akira Matsuda,
    pull request #736 by Leo Gallucci, pull request #746 by DV Suresh.
  • RubyGems now holds exclusive locks on cached gem files to prevent incorrect
    updates. Pull Request #737 by Smit Shah
  • Improved speed of gem install --ignore-dependencies. Patch by Terence
    Lee.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.2.0.rc.1

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.2.0.preview.1

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.11

Bug fixes:

  • Gem::Specification::remove_spec no longer checks for existence of the spec
    to be removed. Issue #698 by Tiago Macedo.
  • Restored wildcard handling when installing gems. Issue #697 by Chuck Remes.
  • Added DigiCert High Assurance EV Root CA certificate for the cloudfront.net
    certificate change.
  • The Gem::RemoteFetcher tests now choose the test server port more reliably.
    Pull Request #706 by akr.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.10

Bug fixes:

  • Use class check instead of :version method check when creating Gem::Version
    objects. Fixes #674 by jkanywhere.
  • Fail during gem update when an error occurs checking for newer versions.
    This means RubyGems no longer reports "nothing to update" when it cannot
    communicate with the server. Issue #688 by Jimmy Dee.
  • Allow installation of gems when the home directory does not exist. Issue
    #689 by Laurence Rowe
  • Fix updating gems which have multiple platforms. Issue #693 by Ookami
    Kenrou.
  • The gem server now uses user-provided directories. Issue #696 by Marcelo
    Alvim.
  • Improved resolution of gems when specific versions have conflicting
    dependencies.
  • RubyGems installs local gems regardless of platform again. Issue #695
  • The --ignore-dependencies option for gem installation works again. Issue
    #695

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.9

Bug fixes:

  • Reduce sorting when fetching specifications. This speeds up the update and
    outdated commands, and others. Issue #657 by windwiny.
  • Proxy usernames and passwords are now escaped properly. Ruby Bug #8979 by
    Masahiro Tomita, Issue #668 by Kouhei Sutou.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.8

Bug fixes:

  • Fixed local installation of platform gem files. Issue #664 by Ryan Melton.
  • Files starting with "." in the root directory are installed again. Issue
    #680 by Ivo Wever, Pull Request #681 by Jeremy Evans.
  • The index generator no longer indexes default gems. Issue #661 by
    Jeremy Hinegardner.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.7

Bug fixes:

  • gem sources --list now displays a list of sources. Pull request #672 by
    Nathan Marley.
  • RubyGems no longer alters Gem::Specification.dirs when installing. Pull
    Request #670 by Vít Ondruch
  • Use RFC 2616-compatible time in HTTP headers. Pull request #655 by Larry
    Marburger.
  • RubyGems now gives a more descriptive message for missing licenses on
    validation. Issue #656 by Markus Heiler.
  • Expand unpack destination directory. This fixes problems when File.realpath
    is missing and $GEM_HOME contains "..". Issue #679 by Charles Nutter.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.6

Bug fixes:

  • Added certificates to follow the s3.amazonaws.com certificate change. Fixes
    #665 by emeyekayee. Fixes #671 by jonforums.
  • Remove redundant built-in certificates not needed for https://rubygems.org
    Fixes #654 by Vít Ondruch.
  • Added test for missing certificates for https://s3.amazonaws.com or
    https://rubygems.org. Pull request #673 by Hannes Georg.
  • RubyGems now allows a Pathname for Kernel#require like the built-in
    Kernel#require. Pull request #663 by Aaron Patterson.
  • Required rbconfig in Gem::ConfigFile for Ruby 1.9.1 compatibility. (Ruby
    1.9.1 is no longer receiving security fixes, so please update to a newer
    version.) Issue #676 by Michal Papis. Issue wayneeseguin/rvm#2262 by
    Thomas Sänger.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.5

Security fixes:

  • RubyGems 2.1.4 and earlier are vulnerable to excessive CPU usage due to a
    backtracking in Gem::Version validation. See CVE-2013-4363 for full details
    including vulnerable APIs. Fixed versions include 2.1.5, 2.0.10, 1.8.27 and
    1.8.23.2 (for Ruby 1.9.3).

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.4

Bug fixes:

  • gem uninstall foo --all now force-uninstalls all versions of foo. Issue
    #650 by Kyle (remkade).
  • Fixed uninstalling gems installed in the home directory (as in
    --user-install). Issue #653 by Lin Jen-Shin.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.3

Bug fixes:

  • Gems with files entries starting with "./" no longer install 0 files. Issue
    #644 by Darragh Curran, #645 by Brandon Turner, #646 by Alex Tambellini

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.2

Bug fixes:

  • Restore concurrent requires following the fix for ruby bug #8374. Pull
    request #637 and issue #640 by Charles Nutter.
  • Gems with extensions are now installed correctly when the --install-dir
    option is used. Issue #642 by Lin Jen-Shin.
  • Gem fetch now fetches the newest (not oldest) gem when --version is given.
    Issue #643 by Brian Shirai.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.1

Bug fixes:

  • Only matching gems matching your local platform are considered for
    installation. Issue #638 by José M. Prieto, issue #639 by sawanoboly.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.1.0

Security fixes:

  • RubyGems 2.0.7 and earlier are vulnerable to excessive CPU usage due to a
    backtracking in Gem::Version validation. See CVE-2013-4287 for full details
    including vulnerable APIs. Fixed versions include 2.0.8, 1.8.26 and
    1.8.23.1 (for Ruby 1.9.3). Issue #626 by Damir Sharipov.

Enhancements:

  • RubyGems uses a new dependency resolver for gem installation which works
    similar to the bundler resolver. The new resolver can resolve conflicts the
    previous resolver could not and offers improved diagnostics when conflicts
    are discovered.

  • RubyGems now has improved platform matching for the ARM architecture. Gems
    built with a CPU of "arm" will match any specific ARM CPU. See gem help platform for further details. Fixes #532 by Kim Burgestrand.

  • The --version option now accepts compound requirements the same as in a gem
    dependency. The following invocation will install rails between 4.0.0.beta
    and 4.2:

    gem install rails -v '>= 4.0.0.beta, < 4.2'

    Fixes #531 by Gary S. Weaver

  • gem clean now allows -n as an alias for --dryrun. Pull Request #517
    by Gastón Ramos

  • Added gem update --system to gem help. Pull Request #514 by Vince
    Wadhwani

  • Added PATH to gem env output. Pull Request #490 by Michal Papis

  • Added --host option to gem owner to match other commands using the
    gemcutter API. Pull Request #462 and issue #461 by Hugo Lopes Tavares

  • Added --abort-on-dependent to gem uninstall. This will abort instead of
    asking to uninstall a gem that is depended upon by another gem. Pull
    request #549 by Philip Arndt.

  • RubyGems no longer alters Gem::Specification.dirs when installing. Based on
    Pull Request #452 by Vít Ondruch

  • RubyGems uses ENV['MAKE'] or ENV['make'] over rbconfig.rb's make if present.
    Pull Request #443 by Erik Hollensbe

  • RubyGems can now save remote source cache files in an alternate directory
    controlled by ENV["GEM_SPEC_CACHE"]. Pull Request #489 by Michal Papis

  • Generated private keys are now encrypted. Pull Request #453 by pietro

  • Separated Gem::Request from Gem::RemoteFetcher. Pull Request #283 by Steve
    Klabnik.

  • RubyGems indicates when a .gem's content is corrupt while verifying. Bug
    #519 by William T Nelson.

  • Refactored common installer setup. Pull request #520 by Gastón Ramos

  • Moved activation tests to Gem::Specification. Pull request #521 by Gastón
    Ramos

  • When a --version option with a prerelease version is given RubyGems
    automatically enables prerelease versions but only the last version is
    used. If the first version is a prerelease version this is no longer sticky
    unless an explicit --[no-]prerelease was also given. Fixes part of #531.

  • RubyGems now supports an SSL client certificate. Pull request #550 by
    Robert Kenny.

  • RubyGems now suggests how to fix permission errors. Pull request #553 by
    Odin Dutton.

  • Added support for installing a gem as default gems for alternate ruby
    implementations. Pull request #566 by Charles Nutter.

  • Improved performance of Gem::Specification#load by caching the loaded
    gemspec. Pull request #569 by Charlie Somerville.

  • RubyGems now warns when an unsigned gem is verified if -P was given during
    installation even if the security policy allows unsigned gems and warns when
    an untrusted certificate is seen even if the security policy allows
    untrusted certificates. Issue #474 by Grant Olson

  • RubyGems can now rewrite executables with or without a shebang of
    /usr/bin/env via gem pristine --all --only-executables
    --env-[no-]shebang. Issue #579 by Paul Annesley.

  • RubyGems can now run its tests without OpenSSL. Ruby Bug #8557 by nobu.

  • Improved performance by caching Gem::Version objects and avoiding
    method_missing in Gem::Specification. Pull request #447 by Jon Leighton.

  • Files in a .gem now preserve their modification times. Pull request #582 by
    Jesse Bowes

  • Improved speed of looking up dependencies in SpecFetcher through
    Array#bsearch (when present). Pull request #595 by Andras Suller

  • Added --all option to gem uninstall which removes all gems in GEM_HOME.
    Pull request #584 by Shannon Skipper.

  • Added Gem.find_latest_files which is equivalent to Gem.find_files but only
    returns matching files from the latest version of each gem. Issue #186 by
    Ryan Davis.

  • Improved performance of gem outdated by reducing duplicate work (it is
    still slow, but I see a near 50% improvement for 250 gems on a fast
    connection). See also Gem::Specification::outdated_and_latest_version

Bug fixes:

  • rubygems_plugin.rb files are now only loaded from the latest installed gem.
  • Fixed Gem.clear_paths when Security is defined at top-level. Pull request
    #625 by elarkin
  • Fixed credential creation for gem push when --host is not given. Pull
    request #622 by Arthur Nogueira Neves

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.17

Bug fixes:

  • Tightened API endpoint checks for CVE-2015-3900

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.16

Bug fixes:

  • Backport: Limit API endpoint to original security domain for CVE-2015-3900.
    Fix by claudijd

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.14

Bug fixes:

  • Gem::Specification::remove_spec no longer checks for existence of the spec
    to be removed. Issue #698 by Tiago Macedo.
  • Restored wildcard handling when installing gems. Issue #697 by Chuck Remes.
  • Added DigiCert High Assurance EV Root CA certificate for the cloudfront.net
    certificate change.
  • The Gem::RemoteFetcher tests now choose the test server port more reliably.
    Pull Request #706 by akr.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.13

Bug fixes:

  • Use class check instead of :version method check when creating Gem::Version
    objects. Fixes #674 by jkanywhere.
  • Allow installation of gems when the home directory does not exist. Issue
    #689 by Laurence Rowe
  • Fix updating gems which have multiple platforms. Issue #693 by Ookami
    Kenrou.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.12

Bug fixes:

  • Proxy usernames and passwords are now escaped properly. Ruby Bug #8979 by
    Masahiro Tomita, Issue #668 by Kouhei Sutou.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.11

Bug fixes:

  • Added certificates to follow the s3.amazonaws.com certificate change. Fixes
    #665 by emeyekayee. Fixes #671 by jonforums.
  • Remove redundant built-in certificates not needed for https://rubygems.org
    Fixes #654 by Vít Ondruch.
  • Added test for missing certificates for https://s3.amazonaws.com or
    https://rubygems.org. Pull request #673 by Hannes Georg.
  • RubyGems now allows a Pathname for Kernel#require like the built-in
    Kernel#require. Pull request #663 by Aaron Patterson.
  • Required rbconfig in Gem::ConfigFile for Ruby 1.9.1 compatibility. (Ruby
    1.9.1 is no longer receiving security fixes, so please update to a newer
    version.) Issue #676 by Michal Papis. Issue wayneeseguin/rvm#2262 by
    Thomas Sänger.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.10

Security fixes:

  • RubyGems 2.1.4 and earlier are vulnerable to excessive CPU usage due to a
    backtracking in Gem::Version validation. See CVE-2013-4363 for full details
    including vulnerable APIs. Fixed versions include 2.1.5, 2.0.10, 1.8.27 and
    1.8.23.2 (for Ruby 1.9.3).

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.9

Bug fixes:

  • Gem fetch now fetches the newest (not oldest) gem when --version is given.
    Issue #643 by Brian Shirai.
  • Fixed credential creation for gem push when --host is not given. Pull
    request #622 by Arthur Nogueira Neves

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.8

Security fixes:

  • RubyGems 2.0.7 and earlier are vulnerable to excessive CPU usage due to a
    backtracking in Gem::Version validation. See CVE-2013-4287 for full details
    including vulnerable APIs. Fixed versions include 2.0.8, 1.8.26 and
    1.8.23.1 (for Ruby 1.9.3). Issue #626 by Damir Sharipov.

Bug fixes:

  • Fixed Gem.clear_paths when Security is defined at top-level. Pull request
    #625 by elarkin

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.7

Bug fixes:

  • Extensions may now be built in parallel (therefore gems may be installed in
    parallel). Bug #607 by Hemant Kumar.
  • Changed broken link to RubyGems Bookshelf to point to RubyGems guides. Ruby
    pull request #369 by 謝致邦.
  • Fixed various test failures due to platform differences or poor tests.
    Patches by Yui Naruse and Koichi Sasada.
  • Fixed documentation for Kernel#require.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.6

Bug fixes:

  • Fixed the --no-install and -I options to gem list and friends. Bug
    #593 by Blargel.
  • Fixed crash when installing gems with extensions under the -V flag. Bug
    #601 by Nick Hoffman.
  • Fixed race condition retrieving HTTP connections in Gem::Request on JRuby.
    Bug #597 by Hemant Kumar.
  • Fixed building extensions on ruby 1.9.3 under mingw. Bug #594 by jonforums,
    Bug #599 by Chris Riesbeck
  • Restored default of remote search to gem search.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.3

Bug fixes:

  • Reverted automatic upgrade to HTTPS as it breaks RubyGems APIs. Fixes
    #506 by André Arko
  • Use File.realpath to remove extra / while checking if files are
    installable. Issue #508 by Jacob Evans.
  • When installing RubyGems on JRuby, the standard library is no longer
    deleted. Fixes #504 by Juan Sanchez, #507 by Charles Oliver Nutter.
  • When building extconf.rb extensions use the intermediate destination
    directory. This addresses further issues with C extension building.
  • Use the absolute path to the generated siteconf in case the extension
    changes directories to run extconf.rb (like memcached). Fixes #498 by
    Chris Morris.
  • Fixed default gem key and cert locations. Pull request #511 by Samuel
    Cochran.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.2

Bug fixes:

  • HTTPS URLs are preferred over HTTP URLs. RubyGems will now attempt to
    upgrade any HTTP source to HTTPS. Credit to Alex Gaynor.
  • SSL Certificates are now installed properly. Fixes #491 by hemanth.hm
  • Fixed HTTP to HTTPS upgrade for rubygems.org.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.1

Bug fixes:

  • Lazily load RubyGems.org API credentials to avoid failure during
    RubyGems installation. Bug #465 by Isaac Sanders.
  • RubyGems now picks the latest prerelease to install. Fixes bug #468 by
    Santiago Pastorino.
  • Improved detection of missing Zlib::GzipReader encoding support. Works
    around JRuby-only bug #472 by Matt Beedle.
  • "Done installing documentation" is no longer displayed when documentation
    generation is disabled. Fixes bug #469 by Jeff Sandberg
  • The existing executable check now respects --format-executable. Pull
    request #471 by Jeremy Evans.
  • RubyGems no longer creates gem subdirectories when fetching gems. Fixes
    #482 by Loren Segal.
  • RubyGems does not require OpenSSL like RubyGems 1.8, but still prefers it.
    Fixes #481 by André Arko.
  • RubyGems only fetches specs for list, search and query commands when
    needed like RubyGems 1.x. Fixes bug #487 by bitbuerster, Ruby bug #8019
    by Ike Miller.
  • Allow specification of mode for gem subdirectory creation.
    Ruby bug #7713 by nobu
  • Fix tests when an 'a.rb' exists. Ruby bug #7749 by nobu.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v2.0.0

RubyGems 2.0 includes several new features and many breaking changes. Some of
these changes will cause existing software to break. These changes are a
result of improvements to the internals of RubyGems that make it more
maintainable and improve APIs for RubyGems users.

If you are using bundler be sure to install a 1.3.0.prerelease version or
newer. Older versions of bundler will not work with RubyGems 2.0.

Changes since RubyGems 1.8.25 (including past pre-releases):

Breaking changes:

  • Deprecated Gem.unresolved_deps in favor of
    Gem::Specification.unresolved_deps
  • Merged Gem::Builder into Gem::Package. Use Gem::Package.build(spec)
    instead of Gem::Builder.new(spec).build
  • Merged Gem::Format into Gem::Package. Use Gem::Package.new instead
    of Gem::Format.from_file_by_path
  • Moved Gem::OldFormat to Gem::Package::Old. Gem::Package will
    automatically detect old gems for you, so there is no need to refer to it.
  • Removed Gem::DocManager, replaced by Gem::RDoc and done_installing hook
  • Removed Gem::Package::TarInput in favor of Gem::Package
  • Removed Gem::Package::TarOutput in favor of Gem::Package
  • Removed Gem::RemoteFetcher#open_uri_or_path. (steveklabnik)
  • Removed Gem::SSL in favor of using OpenSSL directly
  • Removed Gem.loaded_path
  • Removed RSS generation from the gem indexer
  • Removed benchmark option from .gemrc
  • Removed broken YAML gemspec support in gem build
  • Removed support for Ruby 1.9.1
  • Removed many deprecated methods

Enhancements:

  • Improved support for default gems shipping with ruby 2.0.0+
  • A gem can have arbitrary metadata through Gem::Specification#metadata
  • gem search now defaults to --remote and is anchored like gem list. Fixes
    #166
  • Added --document to replace --rdoc and --ri. Use --no-document to disable
    documentation, --document=rdoc to only generate rdoc.
  • Only ri-format documentation is generated by default.
  • gem server uses RDoc::Servlet from RDoc 4.0 to generate HTML
    documentation.
  • Add ability to install gems directly from a compatible gemdep
    file (Gemfile, Isolate, gem.deps.rb)
    gem install --file path
  • Add ability to load gem activation information from a gemdeps
    file (Gemfile, Isolate, gem.deps.rb).
    Set RUBYGEMS_GEMDEPS=path to have it loaded. Use - as the path
    to autodetect (current and parent directories are searched).
  • Added gem check --doctor to clean up after failed uninstallation. Bug
    #419 by Erik Hollensbe
  • RubyGems no longer defaults to uninstalling gems if a dependency would be
    broken. Now you must manually say "yes". Pull Request #406 by Shannon
    Skipper.
  • Gem::DependencyInstaller now passes build_args down to the installer.
    Pull Request #412 by Sam Rawlins.
  • Added a cmake builder. Pull request #265 by Allan Espinosa.
  • Removed rubyforge page from gem list output
  • Added --only-executables option to gem pristine. Fixes #326
  • Added -I flag for 'gem query' to exclude installed items
  • Added Gem.install(name, version=default) for interactive sessions
  • Added Gem::FilePermissionError#directory
  • Added Gem::rubygems_version which is like Gem::ruby_version
  • Added RUBYGEMS_HOST documentation to gem env
  • Added a post_installs hook that runs after Gem::DependencyInstaller
    finishes installing a set of gems
  • Added a usage method for Gem::Commands::OwnerCommand. (ffmike)
  • Added an optional type parameter to Gem::Specification#doc_dir.
  • Added announcements url and clarified how to file tickets
  • Added guidance for how to use rdoc and ri in setup command. (jjb)
  • Attempting to install multiple gems with --version is now an error. You
    can specify per-gem versions like rake:0.9.5
  • Clarified Gem::CommandManager example code to avoid multi load problems.
    (baroquebobcat)
  • Corrupt or bad cached specs are now re-downloaded. (cookrn)
  • Extension build arguments are saved from install and reused for pristine
  • If the OS allows it, documentation is built in a forked background
    process. (alexch)
  • Imported gem yank from the gemcutter gem. Fixes #177, #343
  • Packaged gems now contain and verify SHA1 checksums
  • Removed commas from gem update summary so you can paste it back to
    cleanup. (amatsuda)
  • RubyGems will now warn when building gems with prerelease dependencies.
    Fixes #255
  • The RUBYGEMS_HOST environment variable is used to determine appropriate
    API key for pushing or yanking gems
  • Uninstall is now performed in reverse topological order.
  • Users are told what to type when they try to uninstall a gem outside
    GEM_HOME
  • When building gems with non-world-readable files a warning is shown.

Bug fixes:

  • Gem.refresh now maintains the active gem list. Clearing the list would
    cause double-loads which would cause other bugs. Pull Request #427 by
    Jeremy Evans
  • RubyGems now refuses to read the gem push credentials file if it has
    insecure permissions. Pull Request #438 by Shannon Skipper
  • RubyGems now requires a local gem name to end in '.gem'. Issue #407 by
    Santiago Pastorino.
  • Do not allow old-format gems to be installed with a security policy that
    verifies data.
  • Gem installation will fail if RubyGems cannot load the specification from
    the gem. Bug #419 by Erik Hollensbe
  • RubyGems tests now run in FIPS mode. Issue #365 by Vít Ondruch
  • Only update the spec cache when we have permission. Ruby Bug #7509
  • gem install now ignores directories and non .gem files that match the gem
    to install. Bug #407 by Santiago Pastorino.
  • Added PID to setup bin_file while installing RubyGems to protect against
    errors. Fixes #328 by ConradIrwin
  • Added missing require in Gem::Uninstaller when format_executable is set.
    (sakuro)
  • Exact gem command name matches are now chosen even if a longer command
    overlaps the exact name
  • Fixed Gem.loaded_path? with a Pathname instance. (mattetti)
  • Fixed Gem::Dependency.new mismatch with rubygems.org checks
  • Fixed SecurityError in Gem::Specification.load when $SAFE=1. (ged)
  • Fixed SystemStackError with "gem list -r -a" on 1.9 (cldwalker)
  • Fixed gem owners command so that exceptions don't stop the rest of the
    command from completing
  • Fixed gem unpack uninstalled_gem default version picker.
  • Fixed defunct rubyforge urls in gem command line help
  • Fixed documentation for the various hooks collections
  • Fixed documentation generation on setup when the gem directory does not
    exist. Fixes #253
  • Fixed documentation to reflect where defaults overrides are loaded from.
    (ferrous26)
  • Fixed editing of a Makefile with 8-bit characters. Fixes #181
  • Fixed gem loading issue caused by dependencies not resolving.
  • Fixed independent testing of test_gem_package_tar_output. Ruby Bug #4686
    by Shota Fukumori
  • Fixed typo in uninstall message. (sandal)
  • Gem::Requirement#<=> returns nil on non-requirement arg.
  • Gem::Requirement.satisfied_by? raises ArgumentError if given a non-version
    argument
  • Gem::Version#initialize no longer modifies its parameter. (miaout17)
  • Group-writable permissions are now allowed for gem repositories. (ctcherry)
  • Memoized values in Gem::Specification are now reset the version or
    platform changes. Fixes #78
  • More specific errors are raised for bad requirements. (arsduo)
  • Removed reference to 'sources' gem in documentation
  • Removed unused block arguments to avoid creating Proc objects. (k-tsj)
  • RubyGems now asks before overwriting executable wrappers. Ruby Bug #1800
  • The bindir is now created with mkdir_p during install. (voxik)
  • URI scheme matching is no longer case-sensitive. Fixes #322
  • ext/builder now checks $MAKE as well as $make (okkez)

Changes since RubyGems 2.0.0.rc.2:

Bug fixes:

  • Gem.gzip and Gem.gunzip now return strings with BINARY encoding. Issue
    #450 by Jeremy Kemper
  • Fixed placement of executables with --user-install. Ruby bug #7779 by Jon
    Forums.
  • Fixed gem update with --user-install. Ruby bug #7779 by Jon Forums.
  • Fixed test_initialize_user_install for windows. Ruby bug #7885 by Luis
    Lavena.
  • Create extension destination directory before building extensions. Ruby
    Bug #7897 and patch by Kenta Murata.
  • Fixed verification of gems at LowSecurity due to missing signature.
    Thanks to André Arko.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.29

Bug fixes:

  • Fixed installation when the LANG environment variable is empty.
  • Added DigiCert High Assurance EV Root CA to the default SSL certificates for
    cloudfront.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.28

Bug fixes:

  • Added the Verisign Class 3 Public Primary Certification Authority G5
    certificate and its intermediary to follow the s3.amazonaws.com certificate
    change. Fixes #665 by emeyekayee. Fixes #671 by jonforums.
  • Remove redundant built-in certificates not needed for https://rubygems.org
    Fixes #654 by Vít Ondruch.
  • Added test for missing certificates for https://s3.amazonaws.com or
    https://rubygems.org. Pull request #673 by Hannes Georg.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.27

Security fixes:

  • RubyGems 2.1.4 and earlier are vulnerable to excessive CPU usage due to a
    backtracking in Gem::Version validation. See CVE-2013-4363 for full details
    including vulnerable APIs. Fixed versions include 2.1.5, 2.0.10, 1.8.27 and
    1.8.23.2 (for Ruby 1.9.3).

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.26

Security fixes:

  • RubyGems 2.0.7 and earlier are vulnerable to excessive CPU usage due to a
    backtracking in Gem::Version validation. See CVE-2013-4287 for full details
    including vulnerable APIs. Fixed versions include 2.0.8, 1.8.26 and
    1.8.23.1 (for Ruby 1.9.3). Issue #626 by Damir Sharipov.

Bug fixes:

  • Fixed editing of a Makefile with 8-bit characters. Fixes #181

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.25

Bug fixes:

  • Added 11627 to setup bin_file location to protect against errors. Fixes
    #328 by ConradIrwin
  • Specification#ruby_code didn't handle Requirement with multiple
  • Fix error on creating a Version object with a frozen string.
  • Fix incremental index updates
  • Fix missing load_yaml in YAML-related requirement.rb code.
  • Manually backport encoding-aware YAML gemspec

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.24

Bug fixes:

  • Install the .pem files properly. Fixes #320
  • Remove OpenSSL dependency from the http code path

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.23.2

Security fixes:

  • RubyGems 2.1.4 and earlier are vulnerable to excessive CPU usage due to a
    backtracking in Gem::Version validation. See CVE-2013-4363 for full details
    including vulnerable APIs. Fixed versions include 2.1.5, 2.0.10, 1.8.27 and
    1.8.23.2 (for Ruby 1.9.3).

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.23.1

Security fixes:

  • RubyGems 2.0.7 and earlier are vulnerable to excessive CPU usage due to a
    backtracking in Gem::Version validation. See CVE-2013-4287 for full details
    including vulnerable APIs. Fixed versions include 2.0.8, 1.8.26 and
    1.8.23.1 (for Ruby 1.9.3). Issue #626 by Damir Sharipov.

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.23

Security fixes:

  • RubyGems 2.1.4 and earlier are vulnerable to excessive CPU usage due to a
    backtracking in Gem::Version validation. See CVE-2013-4363 for full details
    including vulnerable APIs. Fixed versions include 2.1.5, 2.0.10, 1.8.27 and
    1.8.23.2 (for Ruby 1.9.3).

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.22

Bug fixes:

  • Workaround for psych/syck YAML date parsing issue
  • Don't trust the encoding of ARGV. Fixes #307
  • Quiet default warnings about missing spec variables
  • Read a binary file properly (windows fix)

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.21

Bug fixes:

  • Add workaround for buggy yaml output from 1.9.2
  • Force 1.9.1 to remove it's prelude code. Fixes #305

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.20

Bug fixes:

  • Add --force to gem build to skip validation. Fixes #297
  • Gracefully deal with YAML::PrivateType objects in Marshal'd gemspecs
  • Treat the source as a proper url base. Fixes #304
  • Warn when updating the specs cache fails. Fixes #300

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.19

Bug fixes:

  • Handle loading psych vs syck properly. Fixes #298
  • Make sure Date objects don't leak in via Marshal
  • Perform Date => Time coercion on yaml loading. Fixes #266

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.18

Bug fixes:

  • Use Psych API to emit more compatible YAML
  • Download and write inside gem fetch directly. Fixes #289
  • Honor sysconfdir on 1.8. Fixes #291
  • Search everywhere for a spec for gem spec. Fixes #288
  • Fix Gem.all_load_path. Fixes #171

- Ruby
Published by hsbt 15 days ago

https://github.com/ruby/rubygems - v1.8.17

Enhancements:

  • Add MacRuby to the list of special cases for platforms (ferrous26)
  • Add a default for where to install rubygems itself

Bug fixes:

  • Fixed gem loading issue caused by dependencies not resolving.
  • Fixed umask error when stdlib is required and unresolved dependencies exist.
  • Shebang munging would only take one arg after the cmd
  • Define SUCKAGE better, ie only MRI 1.9.2
  • Propagate env-shebang to the pristine command if set for install.

- Ruby
Published by hsbt 15 days ago