Skip to content

Bump ransack from 4.4.3 to 5.0.2 - #9

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/ransack-5.0.2
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/ransack-5.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown

Bumps ransack from 4.4.3 to 5.0.2.

Release notes

Sourced from ransack's releases.

v5.0.2

Security release.

Fixes a denial of service: a crafted search key (a very long q[...] condition key or q[s] sort value) was parsed in quadratic time, letting an unauthenticated request exhaust CPU. Ransack now rejects an over-long key as invalid. Applies to any endpoint calling ransack; not mitigated by attribute allowlisting.

GHSA-j3f8-w227-4hh8. Also released as 5.0.2 (and fixed in 6.0.0).

5.0.1

Security fix: bounds the multiparameter position in search params (created_at(1i) and friends) and drops malformed keys, closing a memory-exhaustion denial of service where a crafted request such as q[created_at(100000000000i)]=1 made the server allocate an array of that size. Fixed in 4.4.2, 5.0.1 and 6.0.0. Reported by @​connorshea.

GHSA-vxc9-rm8f-p56j: GHSA-vxc9-rm8f-p56j

5.0.0

Breaking changes

  • LIKE wildcards are now escaped on every adapter, with an explicit ESCAPE clause. cont, start, end and their i_/not_/_any/_all variants treat the search term literally; % and _ typed by a user no longer act as wildcards on SQLite and other backends. Use matches to pass a pattern. — #1682, fixes #1581
  • The ActionView::Helpers::Tags::Base#value monkey patch is removed. It let Rails reach private Kernel methods on any form object and broke unrelated forms in host apps (text_field :test raised ArgumentError). — #1690, closes #1485, relates to #1215
  • Combinators are validated and normalised. 'OR', :or and 'Or' all mean or instead of silently becoming AND; under ransack! / ignore_unknown_conditions: false an unrecognised combinator raises Ransack::InvalidSearchError at any nesting depth. — #1694, closes #1465
  • postgres_fields_sort_option is renamed fields_sort_option (the old name still works). NULLS FIRST / NULLS LAST now go through Arel and work on any backend that supports them, not only PostgreSQL. — #1696, closes #1463

Features

  • ignore_blank_values config option: treat blank values as filters (for JSON APIs) instead of ignoring them (the default, for HTML forms). Typed columns treat a blank as NULL. — #1683, closes #722, #1664
  • Length predicates: length_eq, length_lt, length_lteq, length_gt, length_gteq. — #1697, closes #1492, #1655
  • Trilogy adapter support, with a CI job to prove it. — #1698, closes #1500, #1501
  • enum attributes can be searched by label. — #1665
  • Nested groupings in longhand (groupings: / conditions: / combinator:), and long-form condition keys (attributes: / predicate: / values:). — #1430, #1694
  • NULLS FIRST / NULLS LAST on every backend Arel supports. — #1696

Bug fixes

  • Fix low-level c: API silently dropping conditions when a:/v: are arrays of envelope hashes — #1675, closes #1150
  • Prune blank conditions from the c: API at every nesting depth, without mutating the caller's params — #1687, closes #1653
  • Strip whitespace at every level of the params, not just the top — #1688, closes #1414, #1502
  • Make search_form_for / search_form_with / turbo_search_form_for honour a per-search search_key — #1676, closes #1118
  • Read a form field's value back through ransack_alias, so aliased fields survive a round-trip — #1693, closes #689, #1529
  • Fix ActiveModel::RangeError when a huge integer is searched across multiple attributes in one condition — #1691, closes #1523
  • Make _present / _blank produce only IS [NOT] NULL on non-string columns — #1678, closes #1552
  • Fix ransackable_attributes not handling symbol arrays — #1539, closes #1538
  • Fix scopes inside groupings being silently dropped — #1673, closes #1339, #1490
  • Fix a deprecation warning and a correctness bug with arel_extensions >= 2.2 — #1679
  • Cast SQL Server's :datetimeoffset to time — #1689, closes #1479
  • Remove duplicate definitions causing method-redefined warnings — #1677, closes #1434
  • Keep an explicit nil inside an array from discarding the whole condition, for custom predicates — #1657

Compatibility

  • Respect config.active_record.permanent_connection_checkout: lib/ no longer calls the deprecated ActiveRecord::Base.connection, and metadata lookups no longer lease a connection. — #1692, closes #1570

Documentation

... (truncated)

Commits
  • 4c06f81 Version 5.0.2
  • 7ecfe33 Bound search key depth to stop quadratic-time parsing DoS
  • 188a4bd Version 5.0.1
  • 4a3a120 Drop every malformed multiparameter key, not only an out-of-range one
  • a475ca1 fix: Fix DoS vulnerability in multiparameter attribute handling.
  • bc2fc15 Version 5.0.0 (#1703)
  • 6a44665 Fix the nightly Rails-main job and make it runnable on demand (#1702)
  • 53b5bb1 Version 4.5.0 (#1701)
  • e9985a6 Remove the ActionView::Helpers::Tags::Base#value monkey patch (#1690)
  • 0f3a041 Raise on an invalid combinator, and normalise its case (#1694)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 25, 2026
Bumps [ransack](https://github.com/activerecord-hackery/ransack) from 4.4.3 to 5.0.2.
- [Release notes](https://github.com/activerecord-hackery/ransack/releases)
- [Changelog](https://github.com/activerecord-hackery/ransack/blob/main/CHANGELOG.md)
- [Commits](activerecord-hackery/ransack@v4.4.3...v5.0.2)

---
updated-dependencies:
- dependency-name: ransack
  dependency-version: 5.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/bundler/ransack-5.0.2 branch from b802e43 to 6a07329 Compare September 28, 2026 16:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants