Skip to content

bundle: bump the ruby-dependencies group with 3 updates - #191

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/ruby-dependencies-b5a11610f6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/ruby-dependencies-b5a11610f6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the ruby-dependencies group with 3 updates: dalli, brakeman and pg.

Updates dalli from 5.1.1 to 5.2.2

Release notes

Sourced from dalli's releases.

v5.2.2

Security release. Released together with 5.2.2, 5.1.4, 5.0.10, 4.3.7 and 3.2.13: with a namespace, a retried request could read or write a different key (GHSA-m252-9cgf-vx2w); completes the fixes for GHSA-wr87-m4jw-29x5 and GHSA-w39f-xq2m-4g8x from 5.2.1, and fixes regressions from that release. Upgrading is strongly recommended.

Security:

  • Keep the caller's key when retrying a request (GHSA-m252-9cgf-vx2w)
    • With a namespace, a request retried after a transient network error (a timeout, or a connection closed by memcached or a proxy) applied the namespace a second time, so a retried read could return a different key's value and a retried write could overwrite a different key
    • Affects single-key operations since 5.0.3, single-server get_multi since 5.1.0, and get_with_metadata and fetch_with_lock since 4.1.0; fixed in 5.2.2, 5.1.4, 5.0.10 and 4.3.7. Clients without a namespace aren't affected
  • Complete the fix for per-request raw: true on reads (GHSA-wr87-m4jw-29x5)
    • A read made with raw: true doesn't ask for flags, but a reply carrying them anyway (from a proxy or a hostile server) still had its value deserialized. Raw reads now ignore flags in the reply
    • Affects 5.2.1 and earlier; fixed in 5.2.2, 5.1.4, 5.0.10, 4.3.7 and 3.2.13

Bug fixes:

  • get_with_metadata and fetch_with_lock retried the final error raised when a server is marked down, so with down_retry_delay: 0 they retried an unresponsive server forever. They now retry only retryable errors, like other operations
  • Fix a regression in 5.2.1: a get_multi that didn't finish within socket_timeout counted toward socket_max_failures, so two slow get_multi calls in a row marked a healthy server down. It now just closes the connection
  • Fix a regression in 5.2.1: over TLS, every request buffered in a quiet block was sent as its own TLS record and system call (2.5 times slower for a block of 2000 deletes). Each flush is one write again
  • Handle malformed replies from a broken or hostile server or proxy: a negative value size, a hit with no key, or a hit with no s flag could leave the connection out of step or raise a non-Dalli error
  • With decompressed_max_bytes in effect, data after the end of a compressed value's stream was returned as part of the value. It's now ignored, as without the limit
  • With a digest_class whose digests aren't short hex strings, shortening a long key could loop forever. It now raises ArgumentError

Notes:

  • Document how long keys are shortened, and that a short key written in the same form names the same item, in the README's security note (#1200)

Development:

  • Run the Tests, RuboCop and Profiles workflows on pushes to main and the *-stable branches only, so a pull request's branch isn't tested twice (once for the push and once for the pull request) (#1198)

v5.2.1

Security release. Fixes five vulnerabilities, released together in 5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12: a pipelined get_multi returning another key's value (GHSA-p6pm-ch9v-44vx); unbounded retries and routing tokens that add meta flags (GHSA-4qp6-2jcr-596v); unbounded decompression and reply sizes (GHSA-3553-vcg5-72jw); per-request raw: true ignored on reads (GHSA-wr87-m4jw-29x5); and a forked child resending the parent's requests or ending its TLS session (GHSA-w39f-xq2m-4g8x). Upgrading is strongly recommended.

Security:

  • Fix pipelined get_multi returning one key's value for another after an error reply (GHSA-p6pm-ch9v-44vx)
    • The pipelined reply parser took any reply without a body for the end of the batch. An error reply for one key (CLIENT_ERROR, SERVER_ERROR, or EN from a proxy) ended it early, and the replies still on the connection were read as the replies to later commands, so a get could return another key's value
    • Keys are now measured in bytes as sent, after base64 encoding when the key needs it. A key under 250 characters but over 250 bytes on the wire (for example, one with many non-ASCII characters) was the easiest way to cause that error reply. Such keys are now truncated like other long keys; keys that worked before are unchanged
    • Affects the meta protocol since 3.2.0 (the default since 5.0.0); fixed in 5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12
  • Reject routing tokens that add meta flags, and stop retrying an unresponsive server forever (GHSA-4qp6-2jcr-596v)
    • p_token and l_token now reject whitespace and control characters, not just CR, LF and NUL. A space let a token add meta flags to the request it was sent with: changing an item's TTL on a read, creating stub items on a miss, turning a delete into a stale tombstone, or reading a different key
    • Affects 5.1.0 and later; fixed in 5.2.1 and 5.1.3
    • A server that accepted connections but never answered (or dropped the connection on a request) was retried forever, hanging the caller, because each successful reconnect reset the failure count. Requests now fail after socket_max_failures attempts and the server is marked down, as when it can't be reached at all; it gets a full set of attempts again after down_retry_delay
    • Affects all versions; fixed in 5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12
  • Limit decompressed and reply value sizes (GHSA-3553-vcg5-72jw)
    • Values flagged as compressed were inflated without limit, so a small stored value could expand to gigabytes on read, whatever the client's compress or serializer settings. The new decompressed_max_bytes option (default 128 MiB; nil disables it) makes a read that would pass it raise Dalli::UnmarshalError. Custom compressors whose decompress takes only the data keep working, without the limit
    • The value size in a reply was used to read or buffer that many bytes, so a malicious server could make the client allocate gigabytes. Sizes over 1 GiB, memcached's largest item, now raise Dalli::DalliError before reading
    • Affects all versions; fixed in 5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12
  • Honor per-request raw: true on reads, and add Dalli::JSONSerializer (GHSA-wr87-m4jw-29x5)
    • get_multi, get_multi_cas, get_multi_with_metadata, get_cas and get_with_metadata ignored a per-request raw: true and deserialized the value according to its stored flags, so a caller who asked for raw bytes could still have Marshal.load run on data someone else wrote to memcached. They now return the stored bytes
    • The raw part affects get_with_metadata since 4.2.0, and the other methods since they gained per-request options in 5.1.0

... (truncated)

Changelog

Sourced from dalli's changelog.

5.2.2

Security:

  • Keep the caller's key when retrying a request (GHSA-m252-9cgf-vx2w)
    • With a namespace, a request retried after a transient network error (a timeout, or a connection closed by memcached or a proxy) applied the namespace a second time, so a retried read could return a different key's value and a retried write could overwrite a different key
    • Affects single-key operations since 5.0.3, single-server get_multi since 5.1.0, and get_with_metadata and fetch_with_lock since 4.1.0; fixed in 5.2.2, 5.1.4, 5.0.10 and 4.3.7. Clients without a namespace aren't affected
  • Complete the fix for per-request raw: true on reads (GHSA-wr87-m4jw-29x5)
    • A read made with raw: true doesn't ask for flags, but a reply carrying them anyway (from a proxy or a hostile server) still had its value deserialized. Raw reads now ignore flags in the reply
    • Affects 5.2.1 and earlier; fixed in 5.2.2, 5.1.4, 5.0.10, 4.3.7 and 3.2.13

Bug fixes:

  • get_with_metadata and fetch_with_lock retried the final error raised when a server is marked down, so with down_retry_delay: 0 they retried an unresponsive server forever. They now retry only retryable errors, like other operations
  • Fix a regression in 5.2.1: a get_multi that didn't finish within socket_timeout counted toward socket_max_failures, so two slow get_multi calls in a row marked a healthy server down. It now just closes the connection
  • Fix a regression in 5.2.1: over TLS, every request buffered in a quiet block was sent as its own TLS record and system call (2.5 times slower for a block of 2000 deletes). Each flush is one write again
  • Handle malformed replies from a broken or hostile server or proxy: a negative value size, a hit with no key, or a hit with no s flag could leave the connection out of step or raise a non-Dalli error
  • With decompressed_max_bytes in effect, data after the end of a compressed value's stream was returned as part of the value. It's now ignored, as without the limit
  • With a digest_class whose digests aren't short hex strings, shortening a long key could loop forever. It now raises ArgumentError

Notes:

  • Document how long keys are shortened, and that a short key written in the same form names the same item, in the README's security note (#1200)

Development:

  • Run the Tests, RuboCop and Profiles workflows on pushes to main and the *-stable branches only, so a pull request's branch isn't tested twice (once for the push and once for the pull request) (#1198)

5.2.1

Security:

  • Fix pipelined get_multi returning one key's value for another after an error reply (GHSA-p6pm-ch9v-44vx)
    • The pipelined reply parser took any reply without a body for the end of the batch. An error reply for one key (CLIENT_ERROR, SERVER_ERROR, or EN from a proxy) ended it early, and the replies still on the connection were read as the replies to later commands, so a get could return another key's value
    • Keys are now measured in bytes as sent, after base64 encoding when the key needs it. A key under 250 characters but over 250 bytes on the wire (for example, one with many non-ASCII characters) was the easiest way to cause that error reply. Such keys are now truncated like other long keys; keys that worked before are unchanged
    • Affects the meta protocol since 3.2.0 (the default since 5.0.0); fixed in 5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12
  • Reject routing tokens that add meta flags, and stop retrying an unresponsive server forever (GHSA-4qp6-2jcr-596v)
    • p_token and l_token now reject whitespace and control characters, not just CR, LF and NUL. A space let a token add meta flags to the request it was sent with: changing an item's TTL on a read, creating stub items on a miss, turning a delete into a stale tombstone, or reading a different key
    • Affects 5.1.0 and later; fixed in 5.2.1 and 5.1.3
    • A server that accepted connections but never answered (or dropped the connection on a request) was retried forever, hanging the caller, because each successful reconnect reset the failure count. Requests now fail after socket_max_failures attempts and the server is marked down, as when it can't be reached at all; it gets a full set of attempts again after down_retry_delay
    • Affects all versions; fixed in 5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12
  • Limit decompressed and reply value sizes (GHSA-3553-vcg5-72jw)
    • Values flagged as compressed were inflated without limit, so a small stored value could expand to gigabytes on read, whatever the client's compress or serializer settings. The new decompressed_max_bytes option (default 128 MiB; nil disables it) makes a read that would pass it raise Dalli::UnmarshalError. Custom compressors whose decompress takes only the data keep working, without the limit
    • The value size in a reply was used to read or buffer that many bytes, so a malicious server could make the client allocate gigabytes. Sizes over 1 GiB, memcached's largest item, now raise Dalli::DalliError before reading
    • Affects all versions; fixed in 5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12
  • Honor per-request raw: true on reads, and add Dalli::JSONSerializer (GHSA-wr87-m4jw-29x5)
    • get_multi, get_multi_cas, get_multi_with_metadata, get_cas and get_with_metadata ignored a per-request raw: true and deserialized the value according to its stored flags, so a caller who asked for raw bytes could still have Marshal.load run on data someone else wrote to memcached. They now return the stored bytes
    • The raw part affects get_with_metadata since 4.2.0, and the other methods since they gained per-request options in 5.1.0

... (truncated)

Commits
  • a27cfd3 Merge pull request #1205 from petergoldstein/release/5.2.2
  • 1455750 Prepare 5.2.2 release
  • 2be6cc3 Put the test server's extra flags after the key, and fix a misplaced comment
  • dca2533 Raise instead of looping when a digest is too long for a truncated key
  • 2c9b12d Ignore data after the end of the stream in the capped inflate
  • 1cf990d Handle malformed hits in the reply parsers
  • 7175f23 Send each write-buffer flush as one write
  • 8e41599 Don't count a get_multi that runs out of time as a socket failure
  • 15a71c2 Ignore flags in replies to raw reads (GHSA-wr87-m4jw-29x5)
  • 3fad213 Retry only retryable errors in get_with_metadata and fetch_with_lock
  • Additional commits viewable in compare view

Updates brakeman from 8.0.6 to 8.1.0

Release notes

Sourced from brakeman's releases.

8.1.0

  • Update SonarQube report to use generic issue format (@​fffx)
  • Include regex code in validation warnings (@​eliotsykes)
  • Check validation regexes in non-activerecord models (@​eliotsykes)
  • Skip top-level vendor directory before recursive globbing (@​ronocod)
  • Support Rails 7.1+ positional enum syntax in SQL injection check (@​cubasepp / @​Eljees)
  • Recognize Haml::AttributeBuilder.build_class as an escaped output (@​Eljees)
  • Fix frozen string error (@​shaicoleman)
  • Better help and error message for --ensure-latest (#2036)
Changelog

Sourced from brakeman's changelog.

8.1.0 - 2026-09-30

  • Better help and error message for --ensure-latest
  • Fix frozen string error (Shai Coleman)
  • Update Sonar report format (fangxing)
  • Fix frozen src string error
  • Recognize Haml::AttributeBuilder.build_class as an escaped output (Yuriy Tumanov)
  • Include regex code in validation warnings (Eliot Sykes)
  • Check validation regexes in non-activerecord models (Eliot Sykes)
  • Skip top-level vendor directory before recursive globbing (Conor O'Donnell)
  • Support Rails 7.1+ positional enum syntax in SQL injection check (Michael Vogl/Yuriy Tumanov)
Commits
  • c778164 Bump to 8.1.0
  • 4621407 Update CHANGES
  • 26ba01f Support Rails 7.1+ positional enum syntax in SQL injection check (#2051)
  • 8f04922 Skip top-level vendor directory before recursive globbing (#2039)
  • f921f01 Check validation regexes in non-activerecord models (#2053)
  • d62e919 Fix CheckValidationRegex overly broad ignores (#2050)
  • 73bbc99 Recognize Haml::AttributeBuilder.build_class as an escaped output (#2052)
  • 71f8f69 Fix typo in test_format_validation_with_multiline (#2049)
  • 0fd4dbc Add bundle install step to contributing doc (#2047)
  • 5de415c Fix ERB frozen src error (#2048)
  • Additional commits viewable in compare view

Updates pg from 1.6.3 to 1.7.0

Changelog

Sourced from pg's changelog.

v1.7.0 [2026-10-02] Lars Kanis lars@greiz-reinsdorf.de

Added:

  • Add PG::Connection#embed_params and keyword :typename for its parameter casting. #726 This allows to generate SQL strings with embedded parameters for easier debugging.
  • Add PG::Connection#full_protocol_version which is new in PostgreSQL-18 #695
  • Add PG::Result#each_tuple #675
  • Add PG::TypeMap#query_param_encoders to retrieve encoders. #726
  • Deduplicate result field name strings for better performance. #750

Removed:

  • Remove compatibility to ruby < 3.1 and drops support of ruby-2.7 and ruby-3.0. #749
  • Remove GLV unlocking at all functions which process data modifiable in a second thread. #721 This avoids possible premature garbage collection of query parameters and possible VM crash due to concurrent data manipulation.
  • Remove :static_symbol result field names. #691
  • Remove enforced rpath addition when no rpath is configured in rbconfig. #699

Fixes:

  • Limit memory allocation on invalid input into PG::BinaryDecoder::Array. #743
  • Free COPY buffers when decoders raise to avoid possible memory leak in get_copy_data. #742
  • Prevent SQL injection in set_client_encoding. #741
  • Add GC_GUARD to temporary ruby objects for conninfo string to avoid it's GC'ed prematurely. #739
  • Remove option "quirks_mode" from JSON en/decoder to fix compat with json-3.0 gem. #737
  • Respect calendar type of Ruby and PostgreSQL. #725
  • Fix broken set_notice_(receiver|processor) callback after GC.compact. #734
  • Disable DNS resolution in ruby when a service file is used, so that the priority of parameters is equal to libpq. #635
  • Use RARRAY_LENINT to avoid possible overflow. #728
  • Fix possible integer overflow at PG::BinaryEncoder::CopyRow and PG::TextEncoder::CopyRow. #714, #715
  • Avoid possible integer overflow in query parameter encoding. #719
  • Ensure conninfo is a valid C string before closing the connection to avoid a double free of PGconn. #709
  • Raise on a too large input string to PG::TextEncoder::Bytea. #717
  • Check PG::BinaryEncoder::CopyRow array input size instead of producing an invalid output.
  • Remove accidentally copied "static" keyword from Copy and Record encoder. #711
  • Avoid possibility to replace typemap while being used in Copy and Record encoders and decoders. #707
  • Add GC_GUARD's for encoding converted strings sent to the server. #705
  • Fix incomplete transaction commit when thread is shutdown ungracefully. #704
  • Assign VALUE after registration per rb_gc_register_address() #703
  • Update dependencies for binary gems to PostgreSQL-18.6, OpenSSL-3.6.5, krb5-1.22.2 #752
Commits
  • fcf40c5 Add new gem signing certificate
  • d41e07a Merge pull request #753 from larskanis/rm-pgsql-10
  • 8e1ee8f Remove some conditions for PostgreSQL-10
  • 050c56d Fix typo in CHANGELOG and add version note
  • 2c4934e Bump VERSION to 1.7.0
  • f644ba2 Update release notes once more
  • b16542d Merge pull request #752 from larskanis/upd-binaries
  • 66b27c6 Update dependencies for binary gems to
  • 6a07394 Add CHANGELOG entry for pg-1.7.0
  • 5390356 Merge pull request #749 from larskanis/minruby-3.1
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the ruby-dependencies group with 3 updates: [dalli](https://github.com/petergoldstein/dalli), [brakeman](https://github.com/presidentbeef/brakeman) and [pg](https://github.com/ged/ruby-pg).


Updates `dalli` from 5.1.1 to 5.2.2
- [Release notes](https://github.com/petergoldstein/dalli/releases)
- [Changelog](https://github.com/petergoldstein/dalli/blob/main/CHANGELOG.md)
- [Commits](petergoldstein/dalli@v5.1.1...v5.2.2)

Updates `brakeman` from 8.0.6 to 8.1.0
- [Release notes](https://github.com/presidentbeef/brakeman/releases)
- [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md)
- [Commits](presidentbeef/brakeman@v8.0.6...v8.1.0)

Updates `pg` from 1.6.3 to 1.7.0
- [Changelog](https://github.com/ged/ruby-pg/blob/master/CHANGELOG.md)
- [Commits](ged/ruby-pg@v1.6.3...v1.7.0)

---
updated-dependencies:
- dependency-name: dalli
  dependency-version: 5.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby-dependencies
- dependency-name: brakeman
  dependency-version: 8.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: ruby-dependencies
- dependency-name: pg
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants