Commit graph

30 commits

Author SHA1 Message Date
Mislav Marohnić
875ded8c69 Upgrade OpenSSL to 1.0.2f across the board 2016-01-30 18:16:28 +11:00
deepj
c9a3e265ef Upgrade to OpenSSL 1.0.1r and 1.0.2f 2016-01-30 02:03:10 +01:00
deepj
ce36ebe300 Convert MRI definitions to use bz2 tarballs instead of gz ones 2015-12-25 16:41:42 +01:00
deepj
e59482d9f8 Upgrade to OpenSSL 1.0.1q 2015-12-03 20:28:36 +01:00
Reed Loden
0e2281cced Update Ruby download location to use https:// 2015-07-20 12:45:12 -07:00
deepj
d989a9b0bf Upgrade OpenSSL to 1.0.1p 2015-07-09 15:41:39 +02:00
deepj
b7363f749b Upgrade OpenSSL to 1.0.1o 2015-06-12 18:33:59 +02:00
deepj
e3f622ee50 Upgrade OpenSSL to 1.0.1n 2015-06-11 23:38:33 +02:00
deepj
54d0000e06 Upgrade openssl-1.0.1m 2015-03-19 21:10:52 +01:00
deepj
67a0338480 Upgrade openssl-1.0.1l 2015-01-16 08:48:44 +01:00
deepj
56b3989b1c Upgrade openssl-1.0.1k 2015-01-08 22:28:11 +01:00
SHIBATA Hiroshi
5d738abbc9 upgrade openssl-1.0.1j 2014-10-16 09:48:04 +09:00
Holger Just
e90cb88c41 Upgrade OpenSSL library to 1.0.1i
Previous versions of the library contain several vulnerabilities:
https://www.openssl.org/news/secadv_20140806.txt
2014-09-24 14:23:06 +02:00
deg84
ee04b9d3c5 OpenSSL library updated to 1.0.1h
Previous versions of the library contain a vulnerability CVE-2014-0224.
2014-06-06 01:30:29 +09:00
Thomas Johansen
e9d59cb0cc Replace all MD5 checksums with SHA2 checksums 2014-05-23 14:39:41 +07:00
Vadim Golub
7bb33b04af OpenSSL library updated to 1.0.1g
Previous versions of the library contain a vulnerability CVE-2014-0160.
2014-04-08 01:51:57 +03:00
Jose Luis Salas
53920b0fe1 Update libyaml to 0.1.6
Security fix for CVE-2014-2525

Advisory: http://www.ocert.org/advisories/ocert-2014-003.html
2014-03-26 21:17:10 +01:00
Andreas Fuchs
45067e752f Install libyaml 0.1.5 for 2.x rubies also
This should plug the vulnerability to CVE-2013-6393 (and fix #504)
that can still occur in certain systems: If the ruby build process
couldn't find a libyaml that worked, it would build its own vendored
libyaml, which was 0.1.4 (and is vulnerable).

Instead, specify that the build always should install the latest
libyaml & build against that.
2014-02-07 15:41:03 -08:00
SHIBATA Hiroshi
de33fa8af4 rename hostname, ftp.ruby-lang.org is used by ftp protocol too. 2013-09-07 14:54:07 +09:00
SHIBATA Hiroshi
b122c90476 use http, because http://ftp.ruby-lang.org is deliveried by fastly 2013-09-07 12:53:02 +09:00
SHIBATA Hiroshi
df05cd06a1 manually reverted using mirror site. and use https protocols 2013-09-07 07:50:15 +09:00
SHIBATA Hiroshi
af3f77e900 use www.dnsbalance.ring.gr.jp 2013-08-16 10:58:50 +09:00
Mark Przepiora
f556b4a34c Change protocol of the ruby-lang.org server from HTTP to FTP 2013-08-05 23:18:03 -06:00
Mark Madsen
ea21ec4ee3 fixed typo when openssl-1.0.1e was added to ruby 2.0.0 2013-02-11 17:02:43 -07:00
Erik Michaels-Ober
ffef047307 Upgrade to OpenSSL 1.0.1e 2013-02-11 15:39:03 -08:00
Jeremy Kemper
b5baf47dae Upgrade to OpenSSL 1.0.1d, released 2013-02-05 2013-02-08 17:36:08 -07:00
Sam Stephenson
243e6fbecf Support conditional package installation with --if <test> 2013-02-08 16:48:02 -06:00
Sam Stephenson
a0ace79cd7 Explicitly declare OpenSSL condition and URL in the definition files 2013-02-04 17:55:38 -06:00
Jeremy Kemper
959e5cb22b Build OpenSSL for Ruby 2.0 on OS X.
Apple ships a patched, incompatible OpenSSL. We build a compatible
OpenSSL from source.
2013-02-04 11:01:05 -07:00
Mario Alberto Chavez
6fc9929d4c Definition for ruby 2.0.0-rc1 2013-01-07 09:09:09 -08:00