Skip to content

chore(deps): bump the ruby-deps group across 1 directory with 12 updates#2534

Merged
mroderick merged 1 commit intomasterfrom
dependabot/bundler/ruby-deps-f119291714
Mar 20, 2026
Merged

chore(deps): bump the ruby-deps group across 1 directory with 12 updates#2534
mroderick merged 1 commit intomasterfrom
dependabot/bundler/ruby-deps-f119291714

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 20, 2026

Bumps the ruby-deps group with 12 updates in the / directory:

Package From To
nokogiri 1.19.1 1.19.2
pagy 43.3.0 43.4.1
tzinfo-data 1.2025.3 1.2026.1
commonmarker 2.6.3 2.7.0
rails-html-sanitizer 1.6.2 1.7.0
haml_lint 0.70.0 0.72.0
web-console 4.2.1 4.3.0
faker 3.6.0 3.6.1
rspec-rails 8.0.3 8.0.4
rubocop 1.84.2 1.85.1
capybara-playwright-driver 0.5.8 0.5.9
webmock 3.26.1 3.26.2

Updates nokogiri from 1.19.1 to 1.19.2

Release notes

Sourced from nokogiri's releases.

v1.19.2 / 2026-03-19

Dependencies

  • [JRuby] Saxon-HE is updated to 12.7, from 9.6.0-4. Saxon-HE is a transitive dependency of nu.validator:jing, and this update addresses CVEs in Saxon-HE's own transitive dependencies JDOM and dom4j. We don't think this warrants a security release, however we're cutting a patch release to help users whose security scanners are flagging this. #3611 @​flavorjones

SHA256 Checksums

c34d5c8208025587554608e98fd88ab125b29c80f9352b821964e9a5d5cfbd19  nokogiri-1.19.2-aarch64-linux-gnu.gem
7f6b4b0202d507326841a4f790294bf75098aef50c7173443812e3ac5cb06515  nokogiri-1.19.2-aarch64-linux-musl.gem
b7fa1139016f3dc850bda1260988f0d749934a939d04ef2da13bec060d7d5081  nokogiri-1.19.2-arm-linux-gnu.gem
61114d44f6742ff72194a1b3020967201e2eb982814778d130f6471c11f9828c  nokogiri-1.19.2-arm-linux-musl.gem
58d8ea2e31a967b843b70487a44c14c8ba1866daa1b9da9be9dbdf1b43dee205  nokogiri-1.19.2-arm64-darwin.gem
e9d67034bc80ca71043040beea8a91be5dc99b662daa38a2bfb361b7a2cc8717  nokogiri-1.19.2-java.gem
8ccf25eea3363a2c7b3f2e173a3400582c633cfead27f805df9a9c56d4852d1a  nokogiri-1.19.2-x64-mingw-ucrt.gem
7d9af11fda72dfaa2961d8c4d5380ca0b51bc389dc5f8d4b859b9644f195e7a4  nokogiri-1.19.2-x86_64-darwin.gem
fa8feca882b73e871a9845f3817a72e9734c8e974bdc4fbad6e4bc6e8076b94f  nokogiri-1.19.2-x86_64-linux-gnu.gem
93128448e61a9383a30baef041bf1f5817e22f297a1d400521e90294445069a8  nokogiri-1.19.2-x86_64-linux-musl.gem
38fdd8b59db3d5ea9e7dfb14702e882b9bf819198d5bf976f17ebce12c481756  nokogiri-1.19.2.gem

Full Changelog: sparklemotion/nokogiri@v1.19.1...v1.19.2

Changelog

Sourced from nokogiri's changelog.

v1.19.2 / 2026-03-19

Dependencies

  • [JRuby] Saxon-HE is updated to 12.7, from 9.6.0-4. Saxon-HE is a transitive dependency of nu.validator:jing, and this update addresses CVEs in Saxon-HE's own transitive dependencies JDOM and dom4j. We don't think this warrants a security release, however we're cutting a patch release to help users whose security scanners are flagging this. #3611 @​flavorjones
Commits
  • 6f5d025 version bump to v1.19.2
  • 6d4677f dep: upgrade Saxon-HE from 9.6.0-4 to 12.7 [v1.19.x backport] (#3614)
  • acf9527 dep: upgrade Saxon-HE from 9.6.0-4 to 12.7
  • b42e620 Skip compressed file SAX test on libxml2 >= 2.15
  • See full diff in compare view

Updates pagy from 43.3.0 to 43.4.1

Release notes

Sourced from pagy's releases.

Version 43.4.1

Changes in 43.4.1

  • Normalize deprecations

CHANGELOG

Version 43

We needed a leap version to unequivocally signal that it's not just a major version: it's a complete redesign of the legacy code at all levels, usage and API included.

Why 43? Because it's exactly one step beyond "The answer to the ultimate question of life, the Universe, and everything." 😉

Improvements

This version introduces several enhancements, such as new :countish and :keynav_js paginators and improved automation and configuration processes, reducing setup requirements by 99%. The update also includes a simpler API and new interactive development tools, making it a comprehensive upgrade from previous versions.

  • New :countish Paginator
    • Faster than OFFSET and supporting the full UI
  • New Keynav Pagination
    • The pagy-exclusive technique using the fastest keyset pagination alongside all frontend helpers.
  • New interactive dev-tools
    • New PagyWand to integrate the pagy CSS with your app themes.
    • New Pagy AI available right inside your own app.
  • Intelligent automation
  • Simpler API
    • You solely need the pagy method and the @​pagy instance to paginate any collection and use any navigation tag and helper.
    • Methods are autoloaded only if used, and consume no memory otherwise.
    • Methods have narrower scopes and can be overridden without deep knowledge.
  • New documentation
    • Very concise, straightforward, and easy to navigate and understand.

Upgrade to 43

See the Upgrade Guide

Version 43.4.0

... (truncated)

Changelog

Sourced from pagy's changelog.

Version 43.4.1

  • Normalize deprecations

Version 43.4.0

  • Improve stylesheets and docs
  • Improve JavaScript:
    • Add sync method and task
    • Deprecate sync_javascript
    • Simplify build, configuration and docs

Version 43.3.3

  • Fix Request#resolve_page with jsonapi, limit, and missing page param (#885)
  • Fix pagy-tailwind.css inconsistencies
  • Improve ts/js build process and wand help
  • Move the next_tag into the Pagy class

Version 43.3.2

  • Implement NumericUI module to avoid including the numeric helpers in keynav classes
  • Improve offset accessors and update docs
  • Add basic RBS

Version 43.3.1

  • Update assets for a few apps
  • Fix pagy.ts /.js input_nav update
Commits

Updates tzinfo-data from 1.2025.3 to 1.2026.1

Release notes

Sourced from tzinfo-data's releases.

v1.2026.1

Based on version 2026a of the IANA Time Zone Database (https://lists.iana.org/hyperkitty/list/tz-announce@iana.org/message/ASPLBE3A4BAEXIOQ3KZ6EJSJWBU6L53G/).

Commits
  • 5e9d667 Update to tzdata version 2026a.
  • 3a03d35 Rebuild modules for 2026 (adding an additional year of future data).
  • 73971d9 Update copyright years.
  • f73295c Update to Ruby 4.0.
  • See full diff in compare view

Updates commonmarker from 2.6.3 to 2.7.0

Release notes

Sourced from commonmarker's releases.

v2.7.0

What's Changed

New Contributors

Full Changelog: gjtorikian/commonmarker@v2.6.3...v2.7.0

Changelog

Sourced from commonmarker's changelog.

[v2.7.0] - 14-03-2026

What's Changed

New Contributors

Full Changelog: gjtorikian/commonmarker@v2.6.3...v2.7.0

Commits
  • 863a679 Merge pull request #445 from gjtorikian/release/v2.7.0
  • 9205c50 Update CHANGELOG.md
  • 84b1f00 Merge pull request #447 from gjtorikian/add-compact-html-render-option
  • 399a52e Merge pull request #446 from gjtorikian/add-insert-extension
  • ceb9277 Add compact_html render option to suppress newlines in HTML output
  • 22f957b Add insert extension for rendering ++text++ as \<ins>text\</ins>
  • e625b98 [skip test] update changelog
  • 886dfb7 Merge pull request #443 from fukayatsu/add-fenced-getter
  • c9ac53f Merge pull request #444 from gjtorikian/dependabot/cargo/comrak-0.51.0
  • 95cb510 Bump comrak from 0.50.0 to 0.51.0
  • Additional commits viewable in compare view

Updates rails-html-sanitizer from 1.6.2 to 1.7.0

Release notes

Sourced from rails-html-sanitizer's releases.

v1.7.0 / 2026-02-24

  • Add Rails::HTML::Sanitizer.allowed_uri? which delegates to Loofah::HTML5::Scrub.allowed_uri?, allowing the Rails framework to check URI safety without a direct dependency on Loofah.

    The minimum Loofah dependency is now ~> 2.25.

    Mike Dalessio @​flavorjones

Changelog

Sourced from rails-html-sanitizer's changelog.

v1.7.0 / 2026-02-24

  • Add Rails::HTML::Sanitizer.allowed_uri? which delegates to Loofah::HTML5::Scrub.allowed_uri?, allowing the Rails framework to check URI safety without a direct dependency on Loofah.

    The minimum Loofah dependency is now ~> 2.25.

    Mike Dalessio

Commits
  • a8a0413 version bump to v1.7.0
  • ea9e7a4 Merge pull request #214 from rails/add-allowed-uri
  • f26dc35 Add Rails::HTML::Sanitizer.allowed_uri? delegating to Loofah
  • cc83f51 Merge pull request #213 from rails/flavorjones/ruby-4-support
  • ee54515 dev: ruby 4 support
  • 2a8fe89 Merge pull request #208 from rails/dependabot/bundler/rack-3.1.17
  • 2b0ecc7 build(deps-dev): bump rack from 3.1.16 to 3.1.17
  • c7ab9f2 Merge pull request #206 from rails/dependabot/bundler/rack-3.1.16
  • 0283ca4 build(deps-dev): bump rack from 3.1.14 to 3.1.16
  • ba7a284 Merge pull request #204 from rails/dependabot/bundler/rack-3.1.14
  • Additional commits viewable in compare view

Updates haml_lint from 0.70.0 to 0.72.0

Release notes

Sourced from haml_lint's releases.

0.72.0

What's Changed

Full Changelog: sds/haml-lint@v0.71.0...v0.72.0

0.71.0

What's Changed

  • Revert SpaceInsideParens violations in wrapped tag attributes change (#627)

Full Changelog: sds/haml-lint@v0.70.0...v0.71.0

Changelog

Sourced from haml_lint's changelog.

0.72.0

  • Fix SpaceInsideParens violations in wrapped tag attributes

0.71.0

  • Revert SpaceInsideParens violations in wrapped tag attributes change
Commits

Updates web-console from 4.2.1 to 4.3.0

Release notes

Sourced from web-console's releases.

v4.3.0

What's Changed

Changelog

Sourced from web-console's changelog.

4.3.0

  • #342 Always permit IPv4-mapped IPv6 loopback addresses ([@​zunda]).
  • Fixed Rails 8.2.0.alpha support
  • Drop Rails 7.2 support
  • Drop Ruby 3.1 support
Commits
  • 90e3474 Release 4.3.0
  • bdbb391 Merge pull request #344 from fatkodima/fix-filter-proxies
  • 950462c Fix compatiblity with latest rails
  • c1f9252 Merge pull request #345 from fatkodima/fix-ci
  • 6bc7159 Fix CI
  • 859bc60 Merge pull request #342 from zunda/bind-on-ipv6
  • c66460a Always permit IPv4-mapped IPv6 loopback addresses
  • f3d437c Merge pull request #338 from luiscobot/patch-1
  • 5383121 replace close icon with ×
  • 9a5c089 Merge pull request #336 from sambostock/drop-active-model
  • Additional commits viewable in compare view

Updates faker from 3.6.0 to 3.6.1

Release notes

Sourced from faker's releases.

v3.6.1

It's Spring countdown in the Northern hemisphere 🌸

Security, performance improvements and bug fixes

Update development dependencies

New Contributors

Full Changelog: faker-ruby/faker@v3.6.0...v3.6.1

Changelog

Sourced from faker's changelog.

v3.6.1 (2026-03-04)

It's almost Spring time in the Northern hemisphere 🌸

Security, performance improvements and bug fixes

Update development dependencies

New Contributors

Full Changelog: faker-ruby/faker@v3.6.0...v3.6.1


Commits

Updates rspec-rails from 8.0.3 to 8.0.4

Changelog

Sourced from rspec-rails's changelog.

8.0.4 / 2026-03-10

Full Changelog

Released to relax version constraint for rspec to allow 4.0.0.beta1.

Commits

Updates rubocop from 1.84.2 to 1.85.1

Release notes

Sourced from rubocop's releases.

RuboCop v1.85.1

Bug fixes

  • #14958: Fix false positives in Style/FileOpen when File.open is passed as an argument or returned from a method. (@​sferik)
  • #14973: Fix Style/ReduceToHash false positive when accumulator is read in key/value. (@​sferik)
  • #14964: Fix false positives in Style/RedundantParentheses when parenthesizing a range in a block body. (@​koic)

Changes

RuboCop v1.85.0

New features

Bug fixes

  • #14829: Allow classes without a superclass in Style/EmptyClassDefinition. (@​koic)
  • #14873: Fix an error in Style/NegatedWhile when the last expression of an until condition is negated. (@​koic)
  • #14827: Improve Style/EmptyClassDefinition message wording. ([@​bbatsov][])
  • #14800: Fix false obsolete configuration error for extracted cops when loaded as plugins. ([@​bbatsov][])
  • #14928: Fix a false positive for Lint/Void when nil is used in case branch. ([@​5hun-s][])
  • #14857: Fix false positives in Style/IfUnlessModifier when modifier forms are used inside string interpolations. (@​koic)
  • #8773: Fix false positives in Style/HashTransformKeys and Style/HashTransformValues. (@​sferik)
  • #6963: Fix false positives in Lint/Void for each blocks where the return value may be meaningful (e.g., Enumerator#each). (@​sferik)
  • #14931: Ignore directive comments inside comments. (@​koic)
  • #14834: Fix Layout/IndentationWidth false positive for chained method blocks when EnforcedStyleAlignWith is start_of_line. ([@​krororo][])
  • #14756: Fix Lint/Void to detect void expressions in case/when branches. ([@​bbatsov][])
  • #14874: Fix a Parser::ClobberingError in Lint/UselessAssignment when autocorrecting a useless assignment that wraps a block containing another useless assignment. (@​koic)
  • #14880: Fix a false negative in Layout/MultilineAssignmentLayout when using numblock or itblock with SupportedTypes: ['block']. ([@​bbatsov][])

... (truncated)

Changelog

Sourced from rubocop's changelog.

1.85.1 (2026-03-03)

Bug fixes

  • #14958: Fix false positives in Style/FileOpen when File.open is passed as an argument or returned from a method. ([@​sferik][])
  • #14973: Fix Style/ReduceToHash false positive when accumulator is read in key/value. ([@​sferik][])
  • #14964: Fix false positives in Style/RedundantParentheses when parenthesizing a range in a block body. ([@​koic][])

Changes

1.85.0 (2026-02-26)

New features

Bug fixes

  • #14829: Allow classes without a superclass in Style/EmptyClassDefinition. ([@​koic][])
  • #14873: Fix an error in Style/NegatedWhile when the last expression of an until condition is negated. ([@​koic][])
  • #14827: Improve Style/EmptyClassDefinition message wording. ([@​bbatsov][])
  • #14800: Fix false obsolete configuration error for extracted cops when loaded as plugins. ([@​bbatsov][])
  • #14928: Fix a false positive for Lint/Void when nil is used in case branch. ([@​5hun-s][])
  • #14857: Fix false positives in Style/IfUnlessModifier when modifier forms are used inside string interpolations. ([@​koic][])
  • #8773: Fix false positives in Style/HashTransformKeys and Style/HashTransformValues. ([@​sferik][])
  • #6963: Fix false positives in Lint/Void for each blocks where the return value may be meaningful (e.g., Enumerator#each). ([@​sferik][])
  • #14931: Ignore directive comments inside comments. ([@​koic][])
  • #14834: Fix Layout/IndentationWidth false positive for chained method blocks when EnforcedStyleAlignWith is start_of_line. ([@​krororo][])
  • #14756: Fix Lint/Void to detect void expressions in case/when branches. ([@​bbatsov][])
  • #14874: Fix a Parser::ClobberingError in Lint/UselessAssignment when autocorrecting a useless assignment that wraps a block containing another useless assignment. ([@​koic][])
  • #14880: Fix a false negative in Layout/MultilineAssignmentLayout when using numblock or itblock with SupportedTypes: ['block']. ([@​bbatsov][])
  • #11462: Fix over-indentation when autocorrecting nested hashes with Layout/FirstHashElementIndentation. ([@​ydakuka][])
  • #14880: Recognize block on different line from left side of multi-line assignment in Layout/MultilineAssignmentLayout. ([@​sanfrecce-osaka][])

... (truncated)

Commits
  • fd07672 Cut 1.85.1
  • 5c41f90 Update Changelog
  • 5e8e492 Merge pull request #14975 from sferik/fix_14973
  • 90f3780 Fix Style/ReduceToHash false positive when accumulator is read in key/value
  • 90c7959 Merge pull request #14972 from lovro-bikic/relevant-options-digest-cache
  • 3c20e8d Cache relevant options digest
  • e305f79 Merge pull request #14969 from lovro-bikic/autoload-formatter-constants
  • 3f0a304 Autoload formatters; they're required only when actually used
  • eb973f4 Merge pull request #14966 from koic/fix_false_positives_in_style_redundant_pa...
  • 3338a40 [Fix #14964] Fix false positives in Style/RedundantParentheses
  • Additional commits viewable in compare view

Updates capybara-playwright-driver from 0.5.8 to 0.5.9

Commits
  • b4e696b 0.5.9
  • 0d822cb Merge pull request #134 from YusukeIwaki/fix/fill-options-clear-support
  • b574d9d Make fill_options spec compatible with older Ruby
  • 2028e25 Merge pull request #133 from YusukeIwaki/fix-ruby24-ci
  • b9bd595 Support clear option in TextInput#set (fix #132)
  • b80382f fix for Ruby 2.4
  • 5571ba3 Merge pull request #129 from MatheusRich/drop-file
  • 3602eaa Merge pull request #131 from MatheusRich/fix/close-handler-nullifies-wrong-page
  • 8ad17c3 Merge pull request #130 from YusukeIwaki/codex/fix-issue-128-check-id-timeout
  • f36ddf5 Refine Ruby naming in selectable handler
  • Additional commits viewable in compare view

Updates webmock from 3.26.1 to 3.26.2

Release notes

Sourced from webmock's releases.

...

Description has been truncated

@dependabot dependabot bot added dependencies ruby Pull requests that update Ruby code labels Mar 20, 2026
Bumps the ruby-deps group with 12 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [nokogiri](https://github.com/sparklemotion/nokogiri) | `1.19.1` | `1.19.2` |
| [pagy](https://github.com/ddnexus/pagy) | `43.3.0` | `43.4.1` |
| [tzinfo-data](https://github.com/tzinfo/tzinfo-data) | `1.2025.3` | `1.2026.1` |
| [commonmarker](https://github.com/gjtorikian/commonmarker) | `2.6.3` | `2.7.0` |
| [rails-html-sanitizer](https://github.com/rails/rails-html-sanitizer) | `1.6.2` | `1.7.0` |
| [haml_lint](https://github.com/sds/haml-lint) | `0.70.0` | `0.72.0` |
| [web-console](https://github.com/rails/web-console) | `4.2.1` | `4.3.0` |
| [faker](https://github.com/faker-ruby/faker) | `3.6.0` | `3.6.1` |
| [rspec-rails](https://github.com/rspec/rspec-rails) | `8.0.3` | `8.0.4` |
| [rubocop](https://github.com/rubocop/rubocop) | `1.84.2` | `1.85.1` |
| [capybara-playwright-driver](https://github.com/YusukeIwaki/capybara-playwright-driver) | `0.5.8` | `0.5.9` |
| [webmock](https://github.com/bblimke/webmock) | `3.26.1` | `3.26.2` |



Updates `nokogiri` from 1.19.1 to 1.19.2
- [Release notes](https://github.com/sparklemotion/nokogiri/releases)
- [Changelog](https://github.com/sparklemotion/nokogiri/blob/main/CHANGELOG.md)
- [Commits](sparklemotion/nokogiri@v1.19.1...v1.19.2)

Updates `pagy` from 43.3.0 to 43.4.1
- [Release notes](https://github.com/ddnexus/pagy/releases)
- [Changelog](https://github.com/ddnexus/pagy/blob/master/CHANGELOG.md)
- [Commits](ddnexus/pagy@43.3.0...43.4.1)

Updates `tzinfo-data` from 1.2025.3 to 1.2026.1
- [Release notes](https://github.com/tzinfo/tzinfo-data/releases)
- [Commits](tzinfo/tzinfo-data@v1.2025.3...v1.2026.1)

Updates `commonmarker` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/gjtorikian/commonmarker/releases)
- [Changelog](https://github.com/gjtorikian/commonmarker/blob/main/CHANGELOG.md)
- [Commits](gjtorikian/commonmarker@v2.6.3...v2.7.0)

Updates `rails-html-sanitizer` from 1.6.2 to 1.7.0
- [Release notes](https://github.com/rails/rails-html-sanitizer/releases)
- [Changelog](https://github.com/rails/rails-html-sanitizer/blob/main/CHANGELOG.md)
- [Commits](rails/rails-html-sanitizer@v1.6.2...v1.7.0)

Updates `haml_lint` from 0.70.0 to 0.72.0
- [Release notes](https://github.com/sds/haml-lint/releases)
- [Changelog](https://github.com/sds/haml-lint/blob/main/CHANGELOG.md)
- [Commits](sds/haml-lint@v0.70.0...v0.72.0)

Updates `web-console` from 4.2.1 to 4.3.0
- [Release notes](https://github.com/rails/web-console/releases)
- [Changelog](https://github.com/rails/web-console/blob/main/CHANGELOG.markdown)
- [Commits](rails/web-console@v4.2.1...v4.3.0)

Updates `faker` from 3.6.0 to 3.6.1
- [Release notes](https://github.com/faker-ruby/faker/releases)
- [Changelog](https://github.com/faker-ruby/faker/blob/main/CHANGELOG.md)
- [Commits](faker-ruby/faker@v3.6.0...v3.6.1)

Updates `rspec-rails` from 8.0.3 to 8.0.4
- [Changelog](https://github.com/rspec/rspec-rails/blob/main/Changelog.md)
- [Commits](rspec/rspec-rails@v8.0.3...v8.0.4)

Updates `rubocop` from 1.84.2 to 1.85.1
- [Release notes](https://github.com/rubocop/rubocop/releases)
- [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.md)
- [Commits](rubocop/rubocop@v1.84.2...v1.85.1)

Updates `capybara-playwright-driver` from 0.5.8 to 0.5.9
- [Commits](YusukeIwaki/capybara-playwright-driver@0.5.8...0.5.9)

Updates `webmock` from 3.26.1 to 3.26.2
- [Release notes](https://github.com/bblimke/webmock/releases)
- [Changelog](https://github.com/bblimke/webmock/blob/master/CHANGELOG.md)
- [Commits](bblimke/webmock@v3.26.1...v3.26.2)

---
updated-dependencies:
- dependency-name: nokogiri
  dependency-version: 1.19.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
- dependency-name: pagy
  dependency-version: 43.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby-deps
- dependency-name: tzinfo-data
  dependency-version: 1.2026.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby-deps
- dependency-name: commonmarker
  dependency-version: 2.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby-deps
- dependency-name: rails-html-sanitizer
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby-deps
- dependency-name: haml_lint
  dependency-version: 0.72.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: ruby-deps
- dependency-name: web-console
  dependency-version: 4.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: ruby-deps
- dependency-name: faker
  dependency-version: 3.6.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
- dependency-name: rspec-rails
  dependency-version: 8.0.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
- dependency-name: rubocop
  dependency-version: 1.85.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: ruby-deps
- dependency-name: capybara-playwright-driver
  dependency-version: 0.5.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
- dependency-name: webmock
  dependency-version: 3.26.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/bundler/ruby-deps-f119291714 branch from b86821f to 0b01f96 Compare March 20, 2026 20:24
Copy link
Collaborator

@mroderick mroderick left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High confidence - all 12 dependency updates are backward-compatible minor/patch versions. 882 tests pass. No breaking changes affect the app's usage.

mroderick

This comment was marked as outdated.

Copy link
Collaborator

@mroderick mroderick left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency Upgrade Review: ruby-deps group (12 updates)

Summary

All 12 dependency updates are backward-compatible minor/patch versions. 882 tests pass.

Package Details

Package From To Risk Notes
nokogiri 1.19.1 1.19.2 Low Patch - transitive Saxon-HE update
pagy 43.3.0 43.4.1 Low Minor - deprecation normalization
tzinfo-data 2025.3 2026.1 Low Timezone data update
commonmarker 2.6.3 2.7.0 Low Used in dot_markdown helper for markdown rendering
rails-html-sanitizer 1.6.2 1.7.0 Low New method, backward compatible
haml_lint 0.70.0 0.72.0 Low Dev only
web-console 4.2.1 4.3.0 Low Dev only
faker 3.6.0 3.6.1 Low Dev only, security fix
rspec-rails 8.0.3 8.0.4 Low Dev only
rubocop 1.84.2 1.85.1 Low Dev only
capybara-playwright-driver 0.5.8 0.5.9 Low Dev only
webmock 3.26.1 3.26.2 Low Dev only

Test Results

  • 882 tests pass
  • No breaking changes affect the app's usage

Confidence: High

@mroderick mroderick merged commit 2736c71 into master Mar 20, 2026
16 checks passed
@mroderick mroderick deleted the dependabot/bundler/ruby-deps-f119291714 branch March 20, 2026 22:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant