diff --git a/CHANGELOG.md b/CHANGELOG.md index 3389a7dc2..c0b73b5ed 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,11 @@ This project adheres to [Semantic Versioning](http://semver.org/). ## [Unreleased] +## 2.1.1 - 2021-02-08 +### Security +* Fix Code Injection vulnerability in CarrierWave::RMagick (@mshibuya [15bcf8d8](https://github.com/carrierwaveuploader/carrierwave/commit/15bcf8d84f5cf56e9fe5bcdcc2074aafbd45630b), [GHSA-cf3w-g86h-35x4](https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-cf3w-g86h-35x4)) +* Fix SSRF vulnerability in the remote file download feature (@mshibuya [e0f79e36](https://github.com/carrierwaveuploader/carrierwave/commit/e0f79e3678f2b58e98bc72495db1033646d14cd1), [GHSA-fwcm-636p-68r5](https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-fwcm-636p-68r5)) + ## 2.1.0 - 2020-02-16 ### Added * Support authenticated_url for Blackblaze provider(@kevivmatrix [#2444](https://github.com/carrierwaveuploader/carrierwave/pull/2444)) @@ -70,6 +75,14 @@ _No changes._ * Preserve connection cache when eagar-loading fog(@dmitryshagin [#2383](https://github.com/carrierwaveuploader/carrierwave/pull/2383)) * `#recreate_versions!` ignored `:from_version` when versions to recreate are given(@hedgesky [#1879](https://github.com/carrierwaveuploader/carrierwave/pull/1879) [#1164](https://github.com/carrierwaveuploader/carrierwave/issues/1164)) +## 1.3.2 - 2021-02-08 +### Fixed +* Fix Ruby 2.7 deprecations(@aubinlrx [#2462](https://github.com/carrierwaveuploader/carrierwave/pull/2462)) + +### Security +* Fix Code Injection vulnerability in CarrierWave::RMagick (@mshibuya [eb9346df](https://github.com/carrierwaveuploader/carrierwave/commit/eb9346df598a758a5f8c4a338852982fd7f8f6b8), [GHSA-cf3w-g86h-35x4](https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-cf3w-g86h-35x4)) +* Fix SSRF vulnerability in the remote file download feature (@mshibuya [91714add](https://github.com/carrierwaveuploader/carrierwave/commit/91714adda998bc9e8decf5b1f5d260d808761304), [GHSA-fwcm-636p-68r5](https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-fwcm-636p-68r5)) + ## 1.3.1 - 2018-12-29 ### Fixed * Fix `#url_options_supported?` causing nil error(@mshibuya [0b9a64a1](https://github.com/carrierwaveuploader/carrierwave/commit/0b9a64a1bb9f20d1de154dc3bf2e2dd988210220), [#2361](https://github.com/carrierwaveuploader/carrierwave/issues/2361)) diff --git a/lib/carrierwave/version.rb b/lib/carrierwave/version.rb index 120120974..1621969cf 100644 --- a/lib/carrierwave/version.rb +++ b/lib/carrierwave/version.rb @@ -1,3 +1,3 @@ module CarrierWave - VERSION = "2.1.0" + VERSION = "2.1.1" end