- Fix some compatibility issues with FreeBSD. Closes GH-2668 & GH-2669.
- [Nginx] Upgrades preferred Nginx to 1.30.4 from 1.30.3.
- Fix a vulnerability that left the Passenger Watchdog API unauthenticated. This is a breaking change for some installations and scripts: an "empty watchdog_api_server_authorizations" now means no-auth-is-possible instead of auth-is-skipped. This regression was introduced in 5.2.0. CVE number pending.
- Fix a vulnerability that allowed unauthenticated users to use a Passenger Watchdog process to elevate privileges. This regression was introduced in 5.2.0. CVE number pending.
- Updated various library versions used in precompiled binaries (used for e.g. gem installs):
- cmake: 4.3.3 -> 4.4.2
- curl: 8.20.0 -> 8.21.0
- git: 2.54.0 -> 2.55.0
- gnupg: 2.5.20 -> 2.5.21
- libffi: 3.5.2 -> 3.8.0
- libpsl: 0.21.5 -> 0.23.3
- openssl: 3.6.2 -> 3.6.3
- pinentry: 1.3.2 -> 1.3.3
- rubygems: 4.0.12 -> 4.0.18
- rubies:
- 3.3.11 -> 3.3.12
- 3.4.9 -> 3.4.10
- 4.0.5 -> 4.0.6