ci(deps): bump the bundler group across 1 directory with 13 updates#101
Open
dependabot[bot] wants to merge 1 commit into
Open
ci(deps): bump the bundler group across 1 directory with 13 updates#101dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the bundler group with 8 updates in the /spec/dummy directory: | Package | From | To | | --- | --- | --- | | [puma](https://github.com/puma/puma) | `6.6.0` | `7.2.1` | | [actionview](https://github.com/rails/rails) | `8.0.2` | `8.0.4.1` | | [addressable](https://github.com/sporkmonger/addressable) | `2.8.7` | `2.9.0` | | [erb](https://github.com/ruby/erb) | `5.0.1` | `6.0.1.1` | | [net-imap](https://github.com/ruby/net-imap) | `0.5.8` | `0.5.14` | | [rack](https://github.com/rack/rack) | `3.1.16` | `3.1.21` | | [rack-session](https://github.com/rack/rack-session) | `2.1.1` | `2.1.2` | | [rexml](https://github.com/ruby/rexml) | `3.4.1` | `3.4.2` | Updates `puma` from 6.6.0 to 7.2.1 - [Release notes](https://github.com/puma/puma/releases) - [Changelog](https://github.com/puma/puma/blob/main/History.md) - [Commits](puma/puma@v6.6.0...v7.2.1) Updates `actionview` from 8.0.2 to 8.0.4.1 - [Release notes](https://github.com/rails/rails/releases) - [Changelog](https://github.com/rails/rails/blob/v8.1.3/actionview/CHANGELOG.md) - [Commits](rails/rails@v8.0.2...v8.0.4.1) Updates `activerecord` from 8.0.2 to 8.0.4.1 - [Release notes](https://github.com/rails/rails/releases) - [Changelog](https://github.com/rails/rails/blob/v8.1.3/activerecord/CHANGELOG.md) - [Commits](rails/rails@v8.0.2...v8.0.4.1) Updates `activestorage` from 8.0.2 to 8.0.4.1 - [Release notes](https://github.com/rails/rails/releases) - [Changelog](https://github.com/rails/rails/blob/v8.1.3/activestorage/CHANGELOG.md) - [Commits](rails/rails@v8.0.2...v8.0.4.1) Updates `activesupport` from 8.0.2 to 8.0.4.1 - [Release notes](https://github.com/rails/rails/releases) - [Changelog](https://github.com/rails/rails/blob/v8.1.3/activesupport/CHANGELOG.md) - [Commits](rails/rails@v8.0.2...v8.0.4.1) Updates `addressable` from 2.8.7 to 2.9.0 - [Changelog](https://github.com/sporkmonger/addressable/blob/main/CHANGELOG.md) - [Commits](sporkmonger/addressable@addressable-2.8.7...addressable-2.9.0) Updates `erb` from 5.0.1 to 6.0.1.1 - [Release notes](https://github.com/ruby/erb/releases) - [Changelog](https://github.com/ruby/erb/blob/master/NEWS.md) - [Commits](ruby/erb@v5.0.1...v6.0.1.1) Updates `net-imap` from 0.5.8 to 0.5.14 - [Release notes](https://github.com/ruby/net-imap/releases) - [Commits](ruby/net-imap@v0.5.8...v0.5.14) Updates `nokogiri` from 1.18.8 to 1.19.3 - [Release notes](https://github.com/sparklemotion/nokogiri/releases) - [Changelog](https://github.com/sparklemotion/nokogiri/blob/main/CHANGELOG.md) - [Commits](sparklemotion/nokogiri@v1.18.8...v1.19.3) Updates `rack` from 3.1.16 to 3.1.21 - [Release notes](https://github.com/rack/rack/releases) - [Changelog](https://github.com/rack/rack/blob/main/CHANGELOG.md) - [Commits](rack/rack@v3.1.16...v3.1.21) Updates `rack-session` from 2.1.1 to 2.1.2 - [Release notes](https://github.com/rack/rack-session/releases) - [Changelog](https://github.com/rack/rack-session/blob/main/releases.md) - [Commits](rack/rack-session@v2.1.1...v2.1.2) Updates `rexml` from 3.4.1 to 3.4.2 - [Release notes](https://github.com/ruby/rexml/releases) - [Changelog](https://github.com/ruby/rexml/blob/master/NEWS.md) - [Commits](ruby/rexml@v3.4.1...v3.4.2) Updates `uri` from 1.0.3 to 1.1.1 - [Release notes](https://github.com/ruby/uri/releases) - [Commits](ruby/uri@v1.0.3...v1.1.1) --- updated-dependencies: - dependency-name: puma dependency-version: 7.2.1 dependency-type: direct:production dependency-group: bundler - dependency-name: actionview dependency-version: 8.0.4.1 dependency-type: indirect dependency-group: bundler - dependency-name: activerecord dependency-version: 8.0.4.1 dependency-type: indirect dependency-group: bundler - dependency-name: activestorage dependency-version: 8.0.4.1 dependency-type: indirect dependency-group: bundler - dependency-name: activesupport dependency-version: 8.0.4.1 dependency-type: indirect dependency-group: bundler - dependency-name: addressable dependency-version: 2.9.0 dependency-type: indirect dependency-group: bundler - dependency-name: erb dependency-version: 6.0.1.1 dependency-type: indirect dependency-group: bundler - dependency-name: net-imap dependency-version: 0.5.14 dependency-type: indirect dependency-group: bundler - dependency-name: nokogiri dependency-version: 1.19.3 dependency-type: indirect dependency-group: bundler - dependency-name: rack dependency-version: 3.1.21 dependency-type: indirect dependency-group: bundler - dependency-name: rack-session dependency-version: 2.1.2 dependency-type: indirect dependency-group: bundler - dependency-name: rexml dependency-version: 3.4.2 dependency-type: indirect dependency-group: bundler - dependency-name: uri dependency-version: 1.1.1 dependency-type: indirect dependency-group: bundler ... Signed-off-by: dependabot[bot] <support@github.com>
|
|
🔍 CI Quality Check✅ CI Status: success ✅ Tests passed |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the bundler group with 8 updates in the /spec/dummy directory:
6.6.07.2.18.0.28.0.4.12.8.72.9.05.0.16.0.1.10.5.80.5.143.1.163.1.212.1.12.1.23.4.13.4.2Updates
pumafrom 6.6.0 to 7.2.1Release notes
Sourced from puma's releases.
... (truncated)
Changelog
Sourced from puma's changelog.
... (truncated)
Commits
92754acRelease v7.2.1 (#3948)ebe9db37.2.1 backport (#3947)96b5aa6v7.2.0 (#3864)5d7d1ddAdd workers :auto (#3827)b8c4783ci: fix ci - removeappend_as_byteslogic, misc changes (#3861)44a3ac4Fix PR label manager when maintainer comments [ci skip] (#3863)43f5d89Add GOVERNANCE.md, MAINTAINERS (#3826)21afa66Use Minitest 6 where applicable (#3859)ec7dd61ci: Update test_http11.rb for TruffleRuby - string size (#3860)fa89dbeci: addruby 4.0andrails 8.1(#3852)Updates
actionviewfrom 8.0.2 to 8.0.4.1Release notes
Sourced from actionview's releases.
... (truncated)
Commits
a79efedPreparing for 8.0.4.1 releaseac7979bUpdate changelogc79a07dSkip blank attribute names in Action View tag helpers624fe3cPreparing for 8.0.4 release2f3eb21Sync CHANGELOG9ab450aMerge pull request #55490 from Earlopain/bump-rubocop95bee6aMerge pull request #55738 from skipkayhil/hm-nkxzsnnrqqlyrotw529f933Preparing for 8.0.3 release6409b24Merge pull request #55719 from skipkayhil/hm-fix-label-for-namespace0160f42Sync CHANGELOGsUpdates
activerecordfrom 8.0.2 to 8.0.4.1Release notes
Sourced from activerecord's releases.
... (truncated)
Commits
a79efedPreparing for 8.0.4.1 release624fe3cPreparing for 8.0.4 release2f3eb21Sync CHANGELOG6981fd2Merge pull request #55969 from rails/fix-explain-tests-mysql-9.552347e0Merge pull request #55938 from aidanharan/truthy-condition-mssqld282621Merge pull request #55925 from flavorjones/flavorjones/shard-swap-prohibition...511dbf2Merge pull request #55907 from ruyrocha/fix/sqlite3-data-lossbf9219dMerge pull request #55918 from baarde/with-bound-sql-literals865bc77Merge pull request #55332 from zzak/re-54882dee79c4Merge pull request #55778 from ianterrell/ianterrell/fix-autosave-changed-via...Updates
activestoragefrom 8.0.2 to 8.0.4.1Release notes
Sourced from activestorage's releases.
... (truncated)
Commits
a79efedPreparing for 8.0.4.1 releaseac7979bUpdate changelog955284dPrevent glob injection in ActiveStorage DiskService#delete_prefixeda290c8aPrevent path traversal in ActiveStorage DiskService8fcb934Active Storage: Filter user supplied metadata in DirectUploadControllerd7da4efActiveStorage::Streaming limit range requests to a single range2cd933cConfigurable maxmimum streaming chunk size624fe3cPreparing for 8.0.4 release82f2c96Disable GCS tests in CI529f933Preparing for 8.0.3 releaseUpdates
activesupportfrom 8.0.2 to 8.0.4.1Release notes
Sourced from activesupport's releases.
... (truncated)
Commits
a79efedPreparing for 8.0.4.1 releaseac7979bUpdate changelog29154f1Improve performance of NumberToDelimitedConverter6e8a811FixSafeBuffer#%to preserve unsafe statusee2c59eNumberConverter: reject scientific notation5b6ad9dLock some dependencies624fe3cPreparing for 8.0.4 release0ddf2c9Delete test that now fails with new version of benchmark gem3c7a8a8Merge pull request #55864 from RicardoTrindade/patch-200e1dfaMerge pull request #55840 from zzak/asup-xml-mini-bigdecimal-float-precisionUpdates
addressablefrom 2.8.7 to 2.9.0Changelog
Sourced from addressable's changelog.
Commits
0c3e858Revving version and changelog91915c1Fixing additional vulnerable pathsa091e39Add many more adversarial test cases to ensure we don't have any ReDoS regres...463a819Regenerate gemspec on newer rubygems0afcb0bImprove from O(n^2) to O(n)c87f768Fix a ReDoS vulnerability in URI template matching0d7e9b2Fix links for 2.8.9 in CHANGELOG (#573)e209120Update version, gemspec, and CHANGELOG for 2.8.9 (#572)3875874Reduce gem size by excluding test files (#569)3e57cc6CI: back towindows-2022for MRI jobUpdates
erbfrom 5.0.1 to 6.0.1.1Release notes
Sourced from erb's releases.
Changelog
Sourced from erb's changelog.
Commits
9345076Version 6.0.1.1dd34ce4Prohibit def_method on marshal-loaded ERB instancesbbde68fVersion 6.0.143f0876Freeze ERB::Compiler::TrimScanner::ERB_STAG (#100)2aa3a68Fixed bymisspell -w -error -source=text(#99)f91b260Bump step-security/harden-runner from 2.13.1 to 2.13.2 (#98)543500fBump actions/checkout from 5 to 6 (#97)b23452aFix typo in changelog (#96)bbaaf1fVersion 6.0.01f83b25Drop a deprecated constant ERB::RevisionUpdates
net-imapfrom 0.5.8 to 0.5.14Release notes
Sourced from net-imap's releases.
... (truncated)
Commits
4063bc1🔖 Bump version to 0.5.14f79d35b🔀 Merge pull request #665 from ruby/backport/v0.5/STARTTLS-strippingb3ad198🍒 pick 24d5c773d: 🔒🥅 Handle tagged "OK" to incomplete command [backport #664]7a233c5🍒 pick 62eea6ffe: 🔒🥅 Ensure STARTTLS tagged response was handled [backport #664]a530fa7🍒 pick 46636cae8: ❌🔒 Add failing test for STARTTLS stripping [backport #664]6bf02ae🔀 Merge pull request #662 from ruby/backport/v0.5/raw_data-warningsfa478c5🍒 pick be32e712e: 📚 Improve documentation of RawData arguments [backports #661]ca0ca5d🍒 pick 47c72186d: 🐛 Validate RawData and wait to continue literals [backports...3116c7d🍒 pick 0ec4fd351: 🥅 Validate#setquotastorage limit argument [backports #659]bbe901a🍒 pick 0ea729c78: 📚 Update QUOTA rdoc, params, attrs to match RFCs [backports...Updates
nokogirifrom 1.18.8 to 1.19.3Release notes
Sourced from nokogiri's releases.
... (truncated)
Changelog
Sourced from nokogiri's changelog.
Commits
c139a3dversion bump to v1.19.37501a63fix: backtracking in CSS tokenizer rules (v1.19.x backport) (#3627)03e7968test: skip CSS tokenizer benchmarks on JRubyb984b7efix: ReDoS in CSS tokenizer ident rule0092623fix: ReDoS in CSS tokenizer STRING ruleee17d33fix: memory leak in XSLT transform (backport to v1.19.x) (#3624)ce188a3doc: update CHANGELOGcaeaac4fix: memory leak in XSLT transform25220bfdep(test): test against libxml-ruby v6 (#3618)0caeb21doc: add security warnings for untrusted XSLT stylesheetsUpdates
rackfrom 3.1.16 to 3.1.21Changelog
Sourced from rack's changelog.
Commits
ae84311Bump patch version.87961c3Fix typo in test.fd1c23dAddloggerto gemfile.c59d924Fix test expectation.176f468Add Ruby v4.0 to the test matrix.2856934Drop EOL Rubies from external tests.17ce783Limit the number of quoted escapes during multipart parsing367a2a0Add Content-Length size check in Rack::Multipart::Parsera17cb99Fix root prefix bug in Rack::Static59a0966Only do a simple substitution on the x-accel-mapping pathsUpdates
rack-sessionfrom 2.1.1 to 2.1.2Release notes
Sourced from rack-session's releases.
Changelog
Sourced from rack-session's changelog.
Commits
504367bBump patch version.f43638cDon't fall back to unencrypted coder if encryptors are present.dadcfe6Bump actions/checkout from 4 to 5 (#54)4eb9ea8Add top level session spec to validate existing formats.8f94577Add rails to external tests.