Skip to content

Commit 264c763

Browse files
committed
Add v0.3.61 and v1.2.10 from the 0.3 and 1.2 branches.
1 parent ca29f34 commit 264c763

File tree

1 file changed

+19
-0
lines changed

1 file changed

+19
-0
lines changed

CHANGES.md

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -182,6 +182,15 @@
182182
`TZInfo::Country.get('US').zone_identifiers` should be used instead.
183183

184184

185+
## Version 1.2.10 - 19-Jul-2022
186+
187+
* Fixed a relative path traversal bug that could cause arbitrary files to be
188+
loaded with `require` when used with `RubyDataSource`. Please refer to
189+
<https://github.com/tzinfo/tzinfo/security/advisories/GHSA-5cm2-9h8c-rvfx> for
190+
details. CVE-2022-31163.
191+
* Ignore the SECURITY file from Arch Linux's tzdata package. #134.
192+
193+
185194
## Version 1.2.9 - 16-Dec-2020
186195

187196
* Fixed an incorrect `InvalidTimezoneIdentifier` exception raised when loading a
@@ -340,6 +349,16 @@
340349
use other `TimezonePeriod` instance methods instead (issue #7655).
341350

342351

352+
## Version 0.3.61 (tzdata v2022a) - 19-Jul-2022
353+
354+
* Fixed a relative path traversal bug that could cause arbitrary files to be
355+
loaded with `require` from the Ruby load path. Please refer to
356+
<https://github.com/tzinfo/tzinfo/security/advisories/GHSA-5cm2-9h8c-rvfx> for
357+
details. CVE-2022-31163.
358+
* Updated to tzdata version 2022a
359+
(<https://mm.icann.org/pipermail/tz-announce/2022-March/000070.html>).
360+
361+
343362
## Version 0.3.60 (tzdata v2021a) - 6-Feb-2021
344363

345364
* Updated to tzdata version 2021a

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy