Bump brakeman from 8.0.4 to 8.0.5#76
Conversation
Bumps [brakeman](https://github.com/presidentbeef/brakeman) from 8.0.4 to 8.0.5. - [Release notes](https://github.com/presidentbeef/brakeman/releases) - [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md) - [Commits](presidentbeef/brakeman@v8.0.4...v8.0.5) --- updated-dependencies: - dependency-name: brakeman dependency-version: 8.0.5 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps brakeman from 8.0.4 to 8.0.5.
Release notes
Sourced from brakeman's releases.
Changelog
Sourced from brakeman's changelog.
Commits
104443eBump to 8.0.58e61e2aUpdate CHANGESf014c15Merge pull request #2028 from kiskoza/fix/quote_schema_name9227822Merge pull request #2027 from arpitjain099/fix/brakeman-1915-render-partial-t...6788d28Merge pull request #2025 from arpitjain099/fix/sql-fp-compact-blankb7c3906Add quote_schema_name to safe quote method listf95c500test: update line number for still-warns SQL injection case after fixture shift4fba779base_processor: skip hash render-type extraction when type set positionally1e63a41Fix SQL injection false positive for compact_blank/compact on permitted params7ff9e49Merge pull request #2023 from FFederi/fix-haml-chained-raw-crashDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)