Bump the dependencies group across 1 directory with 8 updates#290
Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
Closed
Bump the dependencies group across 1 directory with 8 updates#290dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the dependencies group with 4 updates in the / directory: [rspec-rails](https://github.com/rspec/rspec-rails), [json](https://github.com/ruby/json), [action_text-trix](https://github.com/basecamp/trix) and [timeout](https://github.com/ruby/timeout). Updates `rspec-rails` from 8.0.3 to 8.0.4 - [Changelog](https://github.com/rspec/rspec-rails/blob/main/Changelog.md) - [Commits](rspec/rspec-rails@v8.0.3...v8.0.4) Updates `json` from 2.18.1 to 2.19.2 - [Release notes](https://github.com/ruby/json/releases) - [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md) - [Commits](ruby/json@v2.18.1...v2.19.2) Updates `action_text-trix` from 2.1.16 to 2.1.17 - [Release notes](https://github.com/basecamp/trix/releases) - [Commits](basecamp/trix@v2.1.16...v2.1.17) Updates `loofah` from 2.25.0 to 2.25.1 - [Release notes](https://github.com/flavorjones/loofah/releases) - [Changelog](https://github.com/flavorjones/loofah/blob/main/CHANGELOG.md) - [Commits](flavorjones/loofah@v2.25.0...v2.25.1) Updates `nokogiri` from 1.19.1 to 1.19.2 - [Release notes](https://github.com/sparklemotion/nokogiri/releases) - [Changelog](https://github.com/sparklemotion/nokogiri/blob/main/CHANGELOG.md) - [Commits](sparklemotion/nokogiri@v1.19.1...v1.19.2) Updates `rails-html-sanitizer` from 1.6.2 to 1.7.0 - [Release notes](https://github.com/rails/rails-html-sanitizer/releases) - [Changelog](https://github.com/rails/rails-html-sanitizer/blob/main/CHANGELOG.md) - [Commits](rails/rails-html-sanitizer@v1.6.2...v1.7.0) Updates `rspec-mocks` from 3.13.7 to 3.13.8 - [Changelog](https://github.com/rspec/rspec/blob/rspec-mocks-v3.13.8/rspec-mocks/Changelog.md) - [Commits](rspec/rspec@rspec-mocks-v3.13.7...rspec-mocks-v3.13.8) Updates `timeout` from 0.6.0 to 0.6.1 - [Release notes](https://github.com/ruby/timeout/releases) - [Commits](ruby/timeout@v0.6.0...v0.6.1) --- updated-dependencies: - dependency-name: rspec-rails dependency-version: 8.0.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: json dependency-version: 2.19.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: action_text-trix dependency-version: 2.1.17 dependency-type: indirect update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: loofah dependency-version: 2.25.1 dependency-type: indirect update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: nokogiri dependency-version: 1.19.2 dependency-type: indirect update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: rails-html-sanitizer dependency-version: 1.7.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: rspec-mocks dependency-version: 3.13.8 dependency-type: indirect update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: timeout dependency-version: 0.6.1 dependency-type: indirect update-type: version-update:semver-patch dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the dependencies group with 4 updates in the / directory: rspec-rails, json, action_text-trix and timeout.
Updates
rspec-railsfrom 8.0.3 to 8.0.4Changelog
Sourced from rspec-rails's changelog.
Commits
222fb55Drop compatibility check rails version to 8.0.0769a3c4v8.0.40549e59Merge pull request #2895 from rspec/add-rspec-4-ci-checkUpdates
jsonfrom 2.18.1 to 2.19.2Release notes
Sourced from json's releases.
Changelog
Sourced from json's changelog.
Commits
54f8a87Release 2.19.2393b41cFix a format string injection vulnerabilitydbf6bb1Merge pull request #953 from ruby/dependabot/github_actions/actions/create-gi...7187315Bump actions/create-github-app-token from 2 to 34a42a04Release 2.19.113689c2Add missing GC_GUARD infbuffer_append_stra11acc1Release 2.19.00a4fb79fbuffer.h: Use size_t over unsigned longa29fcdcAdd depth validation to Jruby and TruffleRuby implementationsde993aaReject negative depth; add overflow guards to prevent hang/crashUpdates
action_text-trixfrom 2.1.16 to 2.1.17Release notes
Sourced from action_text-trix's releases.
Commits
2e46d51v2.1.1753197abMerge pull request #1282 from basecamp/h1-3581911-serialized-attr3229c29Fix stored XSS via data-trix-serialized-attributes sanitizer bypass (H1 #3581...7069343Merge pull request #1239 from Cromian/patch-1d9dbf0aMerge pull request #1280 from basecamp/fix-bullets-merging-with-prior-elementbef13e2Fix bullets merging with prior elements when the first node is removed194a36cMerge pull request #1275 from basecamp/flavorjones/wtr-failure-messagesc94abe6Use source-map to get better test failure messages6f6ab9aTest runner reporter emits failure details1d2d1a3Merge pull request #1276 from basecamp/flavorjones/ci-green-20260109Updates
loofahfrom 2.25.0 to 2.25.1Release notes
Sourced from loofah's releases.
Changelog
Sourced from loofah's changelog.
Commits
c895c8bversion bump to v2.25.1f4ebc9cMerge pull request #302 from flavorjones/flavorjones/better-allowed-uri9f4e5dbUpdateallowed_uri?to handle unescaped whitespace entitiese6f4751doc: Move security reporting to GithubUpdates
nokogirifrom 1.19.1 to 1.19.2Release notes
Sourced from nokogiri's releases.
Changelog
Sourced from nokogiri's changelog.
Commits
6f5d025version bump to v1.19.26d4677fdep: upgrade Saxon-HE from 9.6.0-4 to 12.7 [v1.19.x backport] (#3614)acf9527dep: upgrade Saxon-HE from 9.6.0-4 to 12.7b42e620Skip compressed file SAX test on libxml2 >= 2.15Updates
rails-html-sanitizerfrom 1.6.2 to 1.7.0Release notes
Sourced from rails-html-sanitizer's releases.
Changelog
Sourced from rails-html-sanitizer's changelog.
Commits
a8a0413version bump to v1.7.0ea9e7a4Merge pull request #214 from rails/add-allowed-urif26dc35Add Rails::HTML::Sanitizer.allowed_uri? delegating to Loofahcc83f51Merge pull request #213 from rails/flavorjones/ruby-4-supportee54515dev: ruby 4 support2a8fe89Merge pull request #208 from rails/dependabot/bundler/rack-3.1.172b0ecc7build(deps-dev): bump rack from 3.1.16 to 3.1.17c7ab9f2Merge pull request #206 from rails/dependabot/bundler/rack-3.1.160283ca4build(deps-dev): bump rack from 3.1.14 to 3.1.16ba7a284Merge pull request #204 from rails/dependabot/bundler/rack-3.1.14Updates
rspec-mocksfrom 3.13.7 to 3.13.8Changelog
Sourced from rspec-mocks's changelog.
Commits
712e3carspec-mocks-v3.13.877e3082Changelog for #297efd3f6aMerge pull request #297 from alexdean/any_instance_of_prepend_fix27fe84eChangelog for #286b3ef9b1Tidy up rspec-mocks/spec/rspec/mocks/order_group_spec.rb7ed9f38Improve thread safety of OrderGroups within mocks0404d76Ignore a spec file which issues warningsUpdates
timeoutfrom 0.6.0 to 0.6.1Release notes
Sourced from timeout's releases.
Commits
951e802Bump version to 0.6.19b93553Remove warningse4aa360Fix timing-dependent test55d7c84Compatibility with Fiber scheduler. (#97)35504baMerge pull request #98 from ruby/dependabot/github_actions/step-security/hard...5c0e61eBump step-security/harden-runner from 2.15.0 to 2.15.1f4e1cafMerge pull request #96 from ruby/dependabot/github_actions/step-security/hard...7960b04Bump step-security/harden-runner from 2.14.2 to 2.15.029e4fd3Merge pull request #95 from ruby/dependabot/github_actions/step-security/hard...ccbc5e6Bump step-security/harden-runner from 2.14.1 to 2.14.2Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions