Skip to content

Bump ransack from 4.4.1 to 5.0.2 - #16

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/ransack-5.0.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/ransack-5.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown

Bumps ransack from 4.4.1 to 5.0.2.

Release notes

Sourced from ransack's releases.

v5.0.2

Security release.

Fixes a denial of service: a crafted search key (a very long q[...] condition key or q[s] sort value) was parsed in quadratic time, letting an unauthenticated request exhaust CPU. Ransack now rejects an over-long key as invalid. Applies to any endpoint calling ransack; not mitigated by attribute allowlisting.

GHSA-j3f8-w227-4hh8. Also released as 5.0.2 (and fixed in 6.0.0).

5.0.1

Security fix: bounds the multiparameter position in search params (created_at(1i) and friends) and drops malformed keys, closing a memory-exhaustion denial of service where a crafted request such as q[created_at(100000000000i)]=1 made the server allocate an array of that size. Fixed in 4.4.2, 5.0.1 and 6.0.0. Reported by @​connorshea.

GHSA-vxc9-rm8f-p56j: GHSA-vxc9-rm8f-p56j

5.0.0

Breaking changes

  • LIKE wildcards are now escaped on every adapter, with an explicit ESCAPE clause. cont, start, end and their i_/not_/_any/_all variants treat the search term literally; % and _ typed by a user no longer act as wildcards on SQLite and other backends. Use matches to pass a pattern. — #1682, fixes #1581
  • The ActionView::Helpers::Tags::Base#value monkey patch is removed. It let Rails reach private Kernel methods on any form object and broke unrelated forms in host apps (text_field :test raised ArgumentError). — #1690, closes #1485, relates to #1215
  • Combinators are validated and normalised. 'OR', :or and 'Or' all mean or instead of silently becoming AND; under ransack! / ignore_unknown_conditions: false an unrecognised combinator raises Ransack::InvalidSearchError at any nesting depth. — #1694, closes #1465
  • postgres_fields_sort_option is renamed fields_sort_option (the old name still works). NULLS FIRST / NULLS LAST now go through Arel and work on any backend that supports them, not only PostgreSQL. — #1696, closes #1463

Features

  • ignore_blank_values config option: treat blank values as filters (for JSON APIs) instead of ignoring them (the default, for HTML forms). Typed columns treat a blank as NULL. — #1683, closes #722, #1664
  • Length predicates: length_eq, length_lt, length_lteq, length_gt, length_gteq. — #1697, closes #1492, #1655
  • Trilogy adapter support, with a CI job to prove it. — #1698, closes #1500, #1501
  • enum attributes can be searched by label. — #1665
  • Nested groupings in longhand (groupings: / conditions: / combinator:), and long-form condition keys (attributes: / predicate: / values:). — #1430, #1694
  • NULLS FIRST / NULLS LAST on every backend Arel supports. — #1696

Bug fixes

  • Fix low-level c: API silently dropping conditions when a:/v: are arrays of envelope hashes — #1675, closes #1150
  • Prune blank conditions from the c: API at every nesting depth, without mutating the caller's params — #1687, closes #1653
  • Strip whitespace at every level of the params, not just the top — #1688, closes #1414, #1502
  • Make search_form_for / search_form_with / turbo_search_form_for honour a per-search search_key — #1676, closes #1118
  • Read a form field's value back through ransack_alias, so aliased fields survive a round-trip — #1693, closes #689, #1529
  • Fix ActiveModel::RangeError when a huge integer is searched across multiple attributes in one condition — #1691, closes #1523
  • Make _present / _blank produce only IS [NOT] NULL on non-string columns — #1678, closes #1552
  • Fix ransackable_attributes not handling symbol arrays — #1539, closes #1538
  • Fix scopes inside groupings being silently dropped — #1673, closes #1339, #1490
  • Fix a deprecation warning and a correctness bug with arel_extensions >= 2.2 — #1679
  • Cast SQL Server's :datetimeoffset to time — #1689, closes #1479
  • Remove duplicate definitions causing method-redefined warnings — #1677, closes #1434
  • Keep an explicit nil inside an array from discarding the whole condition, for custom predicates — #1657

Compatibility

  • Respect config.active_record.permanent_connection_checkout: lib/ no longer calls the deprecated ActiveRecord::Base.connection, and metadata lookups no longer lease a connection. — #1692, closes #1570

Documentation

... (truncated)

Commits
  • 4c06f81 Version 5.0.2
  • 7ecfe33 Bound search key depth to stop quadratic-time parsing DoS
  • 188a4bd Version 5.0.1
  • 4a3a120 Drop every malformed multiparameter key, not only an out-of-range one
  • a475ca1 fix: Fix DoS vulnerability in multiparameter attribute handling.
  • bc2fc15 Version 5.0.0 (#1703)
  • 6a44665 Fix the nightly Rails-main job and make it runnable on demand (#1702)
  • 53b5bb1 Version 4.5.0 (#1701)
  • e9985a6 Remove the ActionView::Helpers::Tags::Base#value monkey patch (#1690)
  • 0f3a041 Raise on an invalid combinator, and normalise its case (#1694)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ransack](https://github.com/activerecord-hackery/ransack) from 4.4.1 to 5.0.2.
- [Release notes](https://github.com/activerecord-hackery/ransack/releases)
- [Changelog](https://github.com/activerecord-hackery/ransack/blob/main/CHANGELOG.md)
- [Commits](activerecord-hackery/ransack@v4.4.1...v5.0.2)

---
updated-dependencies:
- dependency-name: ransack
  dependency-version: 5.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants