Bump the ruby-minor-patch group across 1 directory with 14 updates#3604
Open
dependabot[bot] wants to merge 1 commit into
Open
Bump the ruby-minor-patch group across 1 directory with 14 updates#3604dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the ruby-minor-patch group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | [bootsnap](https://github.com/rails/bootsnap) | `1.23.0` | `1.24.6` | | [kamal](https://github.com/basecamp/kamal) | `2.11.0` | `2.12.0` | | [thruster](https://github.com/basecamp/thruster) | `0.1.20` | `0.1.23` | | [view_component](https://github.com/viewcomponent/view_component) | `4.7.0` | `4.12.0` | | [devise](https://github.com/heartcombo/devise) | `5.0.3` | `5.0.4` | | [loofah](https://github.com/flavorjones/loofah) | `2.25.1` | `2.25.2` | | [rails-html-sanitizer](https://github.com/rails/rails-html-sanitizer) | `1.7.0` | `1.7.1` | | [nokogiri](https://github.com/sparklemotion/nokogiri) | `1.19.2` | `1.19.4` | | [activerecord-session_store](https://github.com/rails/activerecord-session_store) | `2.2.0` | `2.3.0` | | [sentry-ruby](https://github.com/getsentry/sentry-ruby) | `6.5.0` | `6.6.2` | | [twilio-ruby](https://github.com/twilio/twilio-ruby) | `7.10.5` | `7.10.7` | | [bullet](https://github.com/flyerhzm/bullet) | `8.1.0` | `8.1.3` | | [selenium-webdriver](https://github.com/SeleniumHQ/selenium) | `4.43.0` | `4.46.0` | Updates `bootsnap` from 1.23.0 to 1.24.6 - [Release notes](https://github.com/rails/bootsnap/releases) - [Changelog](https://github.com/rails/bootsnap/blob/main/CHANGELOG.md) - [Commits](rails/bootsnap@v1.23.0...v1.24.6) Updates `kamal` from 2.11.0 to 2.12.0 - [Release notes](https://github.com/basecamp/kamal/releases) - [Commits](basecamp/kamal@v2.11.0...v2.12.0) Updates `thruster` from 0.1.20 to 0.1.23 - [Changelog](https://github.com/basecamp/thruster/blob/main/CHANGELOG.md) - [Commits](basecamp/thruster@v0.1.20...v0.1.23) Updates `view_component` from 4.7.0 to 4.12.0 - [Release notes](https://github.com/viewcomponent/view_component/releases) - [Changelog](https://github.com/ViewComponent/view_component/blob/main/docs/CHANGELOG.md) - [Commits](ViewComponent/view_component@v4.7.0...v4.12.0) Updates `devise` from 5.0.3 to 5.0.4 - [Release notes](https://github.com/heartcombo/devise/releases) - [Changelog](https://github.com/heartcombo/devise/blob/main/CHANGELOG.md) - [Commits](heartcombo/devise@v5.0.3...v5.0.4) Updates `loofah` from 2.25.1 to 2.25.2 - [Release notes](https://github.com/flavorjones/loofah/releases) - [Changelog](https://github.com/flavorjones/loofah/blob/main/CHANGELOG.md) - [Commits](flavorjones/loofah@v2.25.1...v2.25.2) Updates `rails-html-sanitizer` from 1.7.0 to 1.7.1 - [Release notes](https://github.com/rails/rails-html-sanitizer/releases) - [Changelog](https://github.com/rails/rails-html-sanitizer/blob/main/CHANGELOG.md) - [Commits](rails/rails-html-sanitizer@v1.7.0...v1.7.1) Updates `nokogiri` from 1.19.2 to 1.19.4 - [Release notes](https://github.com/sparklemotion/nokogiri/releases) - [Changelog](https://github.com/sparklemotion/nokogiri/blob/main/CHANGELOG.md) - [Commits](sparklemotion/nokogiri@v1.19.2...v1.19.4) Updates `activerecord-session_store` from 2.2.0 to 2.3.0 - [Release notes](https://github.com/rails/activerecord-session_store/releases) - [Changelog](https://github.com/rails/activerecord-session_store/blob/main/CHANGELOG.md) - [Commits](rails/activerecord-session_store@v2.2.0...v2.3.0) Updates `sentry-ruby` from 6.5.0 to 6.6.2 - [Release notes](https://github.com/getsentry/sentry-ruby/releases) - [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md) - [Commits](getsentry/sentry-ruby@6.5.0...6.6.2) Updates `sentry-rails` from 6.5.0 to 6.6.2 - [Release notes](https://github.com/getsentry/sentry-ruby/releases) - [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md) - [Commits](getsentry/sentry-ruby@6.5.0...6.6.2) Updates `twilio-ruby` from 7.10.5 to 7.10.7 - [Release notes](https://github.com/twilio/twilio-ruby/releases) - [Changelog](https://github.com/twilio/twilio-ruby/blob/main/CHANGES.md) - [Commits](twilio/twilio-ruby@7.10.5...7.10.7) Updates `bullet` from 8.1.0 to 8.1.3 - [Changelog](https://github.com/flyerhzm/bullet/blob/main/CHANGELOG.md) - [Commits](flyerhzm/bullet@8.1.0...8.1.3) Updates `selenium-webdriver` from 4.43.0 to 4.46.0 - [Release notes](https://github.com/SeleniumHQ/selenium/releases) - [Changelog](https://github.com/SeleniumHQ/selenium/blob/trunk/rb/CHANGES) - [Commits](SeleniumHQ/selenium@selenium-4.43.0...selenium-4.46.0) --- updated-dependencies: - dependency-name: bootsnap dependency-version: 1.24.6 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ruby-minor-patch - dependency-name: kamal dependency-version: 2.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ruby-minor-patch - dependency-name: thruster dependency-version: 0.1.23 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ruby-minor-patch - dependency-name: view_component dependency-version: 4.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ruby-minor-patch - dependency-name: devise dependency-version: 5.0.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ruby-minor-patch - dependency-name: loofah dependency-version: 2.25.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ruby-minor-patch - dependency-name: rails-html-sanitizer dependency-version: 1.7.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ruby-minor-patch - dependency-name: nokogiri dependency-version: 1.19.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ruby-minor-patch - dependency-name: activerecord-session_store dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ruby-minor-patch - dependency-name: sentry-ruby dependency-version: 6.6.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ruby-minor-patch - dependency-name: sentry-rails dependency-version: 6.6.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ruby-minor-patch - dependency-name: twilio-ruby dependency-version: 7.10.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ruby-minor-patch - dependency-name: bullet dependency-version: 8.1.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: ruby-minor-patch - dependency-name: selenium-webdriver dependency-version: 4.46.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: ruby-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the ruby-minor-patch group with 13 updates in the / directory:
1.23.01.24.62.11.02.12.00.1.200.1.234.7.04.12.05.0.35.0.42.25.12.25.21.7.01.7.11.19.21.19.42.2.02.3.06.5.06.6.27.10.57.10.78.1.08.1.34.43.04.46.0Updates
bootsnapfrom 1.23.0 to 1.24.6Release notes
Sourced from bootsnap's releases.
Changelog
Sourced from bootsnap's changelog.
Commits
026e183Release 1.24.6263e346Merge pull request #556 from byroot/remove-canary7c31cd8Check for [Bug #22023] by checking Ruby version rather than a canary54eba76Merge pull request #554 from byroot/namespace-overflowfe963d5bs_cache_path: account for namespace length7b42db6Merge pull request #553 from arpitjain099/chore/declare-workflow-perms113b184ci: add permissions: contents: read to cid6ca050Release 1.24.5579aa0eMerge pull request #552 from byroot/fix-bootsnap-config2884e89Only load config file is directed to by.setupUpdates
kamalfrom 2.11.0 to 2.12.0Release notes
Sourced from kamal's releases.
Commits
bdefb89Bump version for 2.12.08eb9659Fix doc formatting for 2.12.0 release62579aaMerge pull request #1844 from matthewbjones/lock-waitdef0eaeAdd--lock-waitto retry deploy lock acquisitionbf22a93Expect git gc --auto step in push resetting clone test24d3dbbMerge pull request #1795 from leonvogt/kamal-secrets-path-defaultbd3e227Merge pull request #1833 from seeday/mainf2671a5Merge pull request #1860 from creadone/non-ascii-deploy-locke71bab5Merge pull request #1874 from basecamp/dependabot/bundler/bundler-f838d46215583beb8Merge pull request #1875 from basecamp/fix-aws-secrets-test-stubsUpdates
thrusterfrom 0.1.20 to 0.1.23Changelog
Sourced from thruster's changelog.
Commits
168dc1fUpdate version & changelog900411cMerge pull request #140 from rafafloresta/bump-go-1.26.5-security2eb7870Bump Go to 1.26.5 to fix crypto/tls ECH de-anonymization (CVE-2026-42505)3acd601Merge pull request #138 from basecamp/version-0.1.2243dfae9Version 0.1.226c45e38Merge pull request #137 from basecamp/compression-exclude-image-types33ea926Exclude image types from compression043a28eMerge pull request #136 from basecamp/check-fmt-in-ci22e7ee8Check formatting during CIc64f358Merge pull request #135 from basecamp/go-1-26-4Updates
view_componentfrom 4.7.0 to 4.12.0Release notes
Sourced from view_component's releases.
Changelog
Sourced from view_component's changelog.
Commits
4cbdbaaMerge pull request #2649 from ViewComponent/release-4-12-0a8888e1Fix lint and bump allocation ranges02d8896lockfiles50a2bafrelease 4.12.06796b2eMerge commit from fork015f42cclean up changelog5963e48simplify53106beupdate changelog7b05073fix Reused component instances retain stale render context48e5fd2fix for around_render safety gapUpdates
devisefrom 5.0.3 to 5.0.4Release notes
Sourced from devise's releases.
Changelog
Sourced from devise's changelog.
Commits
9ea459dRelease v5.0.4 with sec fix for timeoutable025fe21Merge commit from fork7ca7ed9Add GHSA link to the v5.0.3 sec fix changelog entry [ci skip]605de86Update links to https [ci skip]5e3a8bfBundle update5d20277Cleanup old Rails.version check for db migration path4ffb0b7Fix Gemfile for Rails 7.2, incorrectly testing against 7.1Updates
loofahfrom 2.25.1 to 2.25.2Release notes
Sourced from loofah's releases.
Changelog
Sourced from loofah's changelog.
Commits
2706d7eversion bump to v2.25.21afde0cMerge pull request #308 from flavorjones/security-2252f1be9d8Updateallowed_uri?to decode semicolon-less numeric character references5e91af8Updateallowed_uri?to handle named whitespace character references20867b9Properly restrict SVG href attributes5f3bff4test: opt into JSON comment parsing for sanitizer testdata (#307)b07713dtest: do not run in verbose modebabe7a8doc: update CHANGELOGa8d8d96Merge pull request #305 from flavorjones/drop-protocol-typob52f4b0version bump to 2.25.2.beta1Updates
rails-html-sanitizerfrom 1.7.0 to 1.7.1Release notes
Sourced from rails-html-sanitizer's releases.
Changelog
Sourced from rails-html-sanitizer's changelog.
Commits
4f37e3dversion bump to v1.7.1b4673b9Merge pull request #223 from rails/svg-href-local-ref74dcb80Properly restrict SVG href attributes11ee440Adjust data: URI mediatype tests for loofah 2.25.2 (#222)bc9622cHarden GitHub Actions workflows (#220)3459ffddep(dev): update nokogiri (#219)8aa4bb2build(deps-dev): bump concurrent-ruby from 1.3.6 to 1.3.7 (#218)4ddc0c7dep(dev): update development dependencies (#217)f87abb4Merge pull request #215 from yuri-zubov/reduce-gem-size527b317Reduce gem size by excluding test filesUpdates
nokogirifrom 1.19.2 to 1.19.4Release notes
Sourced from nokogiri's releases.
... (truncated)
Changelog
Sourced from nokogiri's changelog.
Commits
8cfb9daversion bump to v1.19.4a856d1efix: JRuby NONET bypass in XML::Schema (v1.19.x) (#3639)6a0aa1efix(CRuby): use-after-free in Document#encoding= when setter raises (v1.19.x)...f658a54fix: JRuby NONET bypass in XML::Schema39d26fefix(CRuby): use-after-free in Document#encoding= when setter raises04a09ddfix(CRuby): out-of-bounds read in NodeSet#[] with large negative index (v1.19...7799fbdfix: avoid NPE on uninitialized XML::Node structs (v1.19.x) (#3645)ef19e13fix(CRuby): avoid UAF in XML::Attr#value= (v1.19.x) (#3644)5524fa9fix:Document#root=rejects non-element nodes (v1.19.x) (#3643)9891ad1fix(CRuby): use-after-free in XPathContext document lifetime (v1.19.x) (#3641)Updates
activerecord-session_storefrom 2.2.0 to 2.3.0Release notes
Sourced from activerecord-session_store's releases.
Commits
74011f1Avoid ruby warningf53dce2Prepare for 2.3.02cfdc4eMerge pull request #166 from chaffeqa/patch-1aab23c9Add tests to make sure an empty save isn't maded6a5e5eUpdate active_record_store.rbe548d59Optimization: prevent empty COMMIT calls6aa1ffeMerge PR #16107fd8cbUse model reference from env when it is availabled2dcde9Merge pull request #222121f9ffDefault to request's cookies_same_site_protection optionUpdates
sentry-rubyfrom 6.5.0 to 6.6.2Changelog
Sourced from sentry-ruby's changelog.