Skip to content

Bump the gems group with 4 updates - #780

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/bundler/gems-7fd72d601b
Oct 5, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/bundler/gems-7fd72d601b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the gems group with 4 updates: brakeman, honeybadger, lograge and image_processing.

Updates brakeman from 8.0.6 to 8.1.0

Release notes

Sourced from brakeman's releases.

8.1.0

  • Update SonarQube report to use generic issue format (@​fffx)
  • Include regex code in validation warnings (@​eliotsykes)
  • Check validation regexes in non-activerecord models (@​eliotsykes)
  • Skip top-level vendor directory before recursive globbing (@​ronocod)
  • Support Rails 7.1+ positional enum syntax in SQL injection check (@​cubasepp / @​Eljees)
  • Recognize Haml::AttributeBuilder.build_class as an escaped output (@​Eljees)
  • Fix frozen string error (@​shaicoleman)
  • Better help and error message for --ensure-latest (#2036)
Changelog

Sourced from brakeman's changelog.

8.1.0 - 2026-09-30

  • Better help and error message for --ensure-latest
  • Fix frozen string error (Shai Coleman)
  • Update Sonar report format (fangxing)
  • Fix frozen src string error
  • Recognize Haml::AttributeBuilder.build_class as an escaped output (Yuriy Tumanov)
  • Include regex code in validation warnings (Eliot Sykes)
  • Check validation regexes in non-activerecord models (Eliot Sykes)
  • Skip top-level vendor directory before recursive globbing (Conor O'Donnell)
  • Support Rails 7.1+ positional enum syntax in SQL injection check (Michael Vogl/Yuriy Tumanov)
Commits
  • c778164 Bump to 8.1.0
  • 4621407 Update CHANGES
  • 26ba01f Support Rails 7.1+ positional enum syntax in SQL injection check (#2051)
  • 8f04922 Skip top-level vendor directory before recursive globbing (#2039)
  • f921f01 Check validation regexes in non-activerecord models (#2053)
  • d62e919 Fix CheckValidationRegex overly broad ignores (#2050)
  • 73bbc99 Recognize Haml::AttributeBuilder.build_class as an escaped output (#2052)
  • 71f8f69 Fix typo in test_format_validation_with_multiline (#2049)
  • 0fd4dbc Add bundle install step to contributing doc (#2047)
  • 5de415c Fix ERB frozen src error (#2048)
  • Additional commits viewable in compare view

Updates honeybadger from 6.9.2 to 6.9.3

Release notes

Sourced from honeybadger's releases.

v6.9.3

6.9.3 (2026-09-29)

Bug Fixes

  • propagate the Rails request ID to notices and Insights events (#848) (23edb08)
Changelog

Sourced from honeybadger's changelog.

6.9.3 (2026-09-29)

Bug Fixes

  • propagate the Rails request ID to notices and Insights events (#848) (23edb08)
Commits
  • ed14af0 chore(master): release 6.9.3 (#852)
  • 23edb08 fix: propagate the Rails request ID to notices and Insights events (#848)
  • 7705695 ci: migrate release-please action to googleapis/release-please-action@v5 (#846)
  • See full diff in compare view

Updates lograge from 0.15.0 to 0.15.1

Changelog

Sourced from lograge's changelog.

0.15.1

  • Fully suppress Rails' default Action View logs on Rails 7.1+ by also removing ActionView::LogSubscriber::Start #386
  • Declare logger as a runtime dependency in the gemspec, since it is no longer a default gem in newer Rubies #401
Commits
  • 106e833 Release 0.15.1 (#406)
  • f12d78c Release 0.15.1
  • a66e9bf Unsubscribe all Rails built-in subscribers (#386)
  • 82a899d Match Rails log subscribers explicitly instead of by namespace
  • f3b0e21 Merge branch 'master' into unsubscribe_all_action_view_subscribers_in_rails_71
  • d0b1df5 Merge pull request #401 from leoarnold/leoarnold/gemspec
  • dd847eb Add 'logger' as dependency in gemspec
  • d5b43c6 Merge pull request #405 from roidrage/ci/fix-json3-and-rubocop
  • 4939216 ci: run RuboCop once instead of across the whole matrix
  • f3b821d ci: fix pre-existing failures from json 3.x and RuboCop 1.91
  • Additional commits viewable in compare view

Updates image_processing from 2.1.0 to 2.2.0

Changelog

Sourced from image_processing's changelog.

2.2.0 (2026-09-29)

  • Save in the #convert format when the destination path has no extension, such as a /dev/fd/N path (thanks to @​flavorjones)
Commits
  • d9737fb Set version to 2.2.0
  • 8f7b538 Handle missing AVIF encoder in tests
  • 92086c5 Handle AVIF format on extensionless destinations
  • 5827e83 Save in the #convert format to an extensionless destination (#150)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the gems group with 4 updates: [brakeman](https://github.com/presidentbeef/brakeman), [honeybadger](https://github.com/honeybadger-io/honeybadger-ruby), [lograge](https://github.com/roidrage/lograge) and [image_processing](https://github.com/janko/image_processing).


Updates `brakeman` from 8.0.6 to 8.1.0
- [Release notes](https://github.com/presidentbeef/brakeman/releases)
- [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md)
- [Commits](presidentbeef/brakeman@v8.0.6...v8.1.0)

Updates `honeybadger` from 6.9.2 to 6.9.3
- [Release notes](https://github.com/honeybadger-io/honeybadger-ruby/releases)
- [Changelog](https://github.com/honeybadger-io/honeybadger-ruby/blob/master/CHANGELOG.md)
- [Commits](honeybadger-io/honeybadger-ruby@v6.9.2...v6.9.3)

Updates `lograge` from 0.15.0 to 0.15.1
- [Changelog](https://github.com/roidrage/lograge/blob/master/CHANGELOG.md)
- [Commits](roidrage/lograge@v0.15.0...v0.15.1)

Updates `image_processing` from 2.1.0 to 2.2.0
- [Changelog](https://github.com/janko/image_processing/blob/master/CHANGELOG.md)
- [Commits](janko/image_processing@v2.1.0...v2.2.0)

---
updated-dependencies:
- dependency-name: brakeman
  dependency-version: 8.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: gems
- dependency-name: honeybadger
  dependency-version: 6.9.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gems
- dependency-name: lograge
  dependency-version: 0.15.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gems
- dependency-name: image_processing
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gems
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Oct 5, 2026
@github-actions
github-actions Bot merged commit 409831f into main Oct 5, 2026
5 checks passed
@github-actions
github-actions Bot deleted the dependabot/bundler/gems-7fd72d601b branch October 5, 2026 01:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants