Repository navigation
bundle: bump the ruby-dependencies group with 3 updates - #191
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the ruby-dependencies group with 3 updates: [dalli](https://github.com/petergoldstein/dalli), [brakeman](https://github.com/presidentbeef/brakeman) and [pg](https://github.com/ged/ruby-pg). Updates `dalli` from 5.1.1 to 5.2.2 - [Release notes](https://github.com/petergoldstein/dalli/releases) - [Changelog](https://github.com/petergoldstein/dalli/blob/main/CHANGELOG.md) - [Commits](petergoldstein/dalli@v5.1.1...v5.2.2) Updates `brakeman` from 8.0.6 to 8.1.0 - [Release notes](https://github.com/presidentbeef/brakeman/releases) - [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md) - [Commits](presidentbeef/brakeman@v8.0.6...v8.1.0) Updates `pg` from 1.6.3 to 1.7.0 - [Changelog](https://github.com/ged/ruby-pg/blob/master/CHANGELOG.md) - [Commits](ged/ruby-pg@v1.6.3...v1.7.0) --- updated-dependencies: - dependency-name: dalli dependency-version: 5.2.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ruby-dependencies - dependency-name: brakeman dependency-version: 8.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: ruby-dependencies - dependency-name: pg dependency-version: 1.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ruby-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the ruby-dependencies group with 3 updates: dalli, brakeman and pg.
Updates
dallifrom 5.1.1 to 5.2.2Release notes
Sourced from dalli's releases.
... (truncated)
Changelog
Sourced from dalli's changelog.
... (truncated)
Commits
a27cfd3Merge pull request #1205 from petergoldstein/release/5.2.21455750Prepare 5.2.2 release2be6cc3Put the test server's extra flags after the key, and fix a misplaced commentdca2533Raise instead of looping when a digest is too long for a truncated key2c9b12dIgnore data after the end of the stream in the capped inflate1cf990dHandle malformed hits in the reply parsers7175f23Send each write-buffer flush as one write8e41599Don't count a get_multi that runs out of time as a socket failure15a71c2Ignore flags in replies to raw reads (GHSA-wr87-m4jw-29x5)3fad213Retry only retryable errors in get_with_metadata and fetch_with_lockUpdates
brakemanfrom 8.0.6 to 8.1.0Release notes
Sourced from brakeman's releases.
Changelog
Sourced from brakeman's changelog.
Commits
c778164Bump to 8.1.04621407Update CHANGES26ba01fSupport Rails 7.1+ positional enum syntax in SQL injection check (#2051)8f04922Skip top-level vendor directory before recursive globbing (#2039)f921f01Check validation regexes in non-activerecord models (#2053)d62e919Fix CheckValidationRegex overly broad ignores (#2050)73bbc99Recognize Haml::AttributeBuilder.build_class as an escaped output (#2052)71f8f69Fix typo in test_format_validation_with_multiline (#2049)0fd4dbcAdd bundle install step to contributing doc (#2047)5de415cFix ERB frozensrcerror (#2048)Updates
pgfrom 1.6.3 to 1.7.0Changelog
Sourced from pg's changelog.
Commits
fcf40c5Add new gem signing certificated41e07aMerge pull request #753 from larskanis/rm-pgsql-108e1ee8fRemove some conditions for PostgreSQL-10050c56dFix typo in CHANGELOG and add version note2c4934eBump VERSION to 1.7.0f644ba2Update release notes once moreb16542dMerge pull request #752 from larskanis/upd-binaries66b27c6Update dependencies for binary gems to6a07394Add CHANGELOG entry for pg-1.7.05390356Merge pull request #749 from larskanis/minruby-3.1Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions