Repository navigation
Bump the bundler group across 1 directory with 8 updates - #160
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the bundler group with 8 updates in the /android directory: | Package | From | To | | --- | --- | --- | | [addressable](https://github.com/sporkmonger/addressable) | `2.8.7` | `2.9.0` | | [aws-sdk-s3](https://github.com/aws/aws-sdk-ruby) | `1.182.0` | `1.208.0` | | [excon](https://github.com/excon/excon) | `0.112.0` | `1.5.0` | | [faraday](https://github.com/lostisland/faraday) | `1.10.4` | `2.14.4` | | [json](https://github.com/ruby/json) | `2.10.2` | `2.19.9` | | [jwt](https://github.com/jwt/ruby-jwt) | `2.10.1` | `3.3.0` | | [rexml](https://github.com/ruby/rexml) | `3.4.1` | `3.4.4` | | [rubyzip](https://github.com/rubyzip/rubyzip) | `2.4.1` | `3.7.0` | Updates `addressable` from 2.8.7 to 2.9.0 - [Changelog](https://github.com/sporkmonger/addressable/blob/main/CHANGELOG.md) - [Commits](sporkmonger/addressable@addressable-2.8.7...addressable-2.9.0) Updates `aws-sdk-s3` from 1.182.0 to 1.208.0 - [Release notes](https://github.com/aws/aws-sdk-ruby/releases) - [Changelog](https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sdk-s3/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-ruby/commits) Updates `excon` from 0.112.0 to 1.5.0 - [Changelog](https://github.com/excon/excon/blob/master/changelog.txt) - [Commits](excon/excon@v0.112.0...v1.5.0) Updates `faraday` from 1.10.4 to 2.14.4 - [Release notes](https://github.com/lostisland/faraday/releases) - [Changelog](https://github.com/lostisland/faraday/blob/main/CHANGELOG.md) - [Commits](lostisland/faraday@v1.10.4...v2.14.4) Updates `json` from 2.10.2 to 2.19.9 - [Release notes](https://github.com/ruby/json/releases) - [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md) - [Commits](ruby/json@v2.10.2...v2.19.9) Updates `jwt` from 2.10.1 to 3.3.0 - [Release notes](https://github.com/jwt/ruby-jwt/releases) - [Changelog](https://github.com/jwt/ruby-jwt/blob/main/CHANGELOG.md) - [Commits](jwt/ruby-jwt@v2.10.1...v3.3.0) Updates `rexml` from 3.4.1 to 3.4.4 - [Release notes](https://github.com/ruby/rexml/releases) - [Changelog](https://github.com/ruby/rexml/blob/master/NEWS.md) - [Commits](ruby/rexml@v3.4.1...v3.4.4) Updates `rubyzip` from 2.4.1 to 3.7.0 - [Release notes](https://github.com/rubyzip/rubyzip/releases) - [Changelog](https://github.com/rubyzip/rubyzip/blob/main/Changelog.md) - [Commits](rubyzip/rubyzip@v2.4.1...v3.7.0) --- updated-dependencies: - dependency-name: addressable dependency-version: 2.9.0 dependency-type: indirect dependency-group: bundler - dependency-name: aws-sdk-s3 dependency-version: 1.208.0 dependency-type: indirect dependency-group: bundler - dependency-name: excon dependency-version: 1.5.0 dependency-type: indirect dependency-group: bundler - dependency-name: faraday dependency-version: 2.14.4 dependency-type: indirect dependency-group: bundler - dependency-name: json dependency-version: 2.19.9 dependency-type: indirect dependency-group: bundler - dependency-name: jwt dependency-version: 3.3.0 dependency-type: indirect dependency-group: bundler - dependency-name: rexml dependency-version: 3.4.4 dependency-type: indirect dependency-group: bundler - dependency-name: rubyzip dependency-version: 3.7.0 dependency-type: indirect dependency-group: bundler ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the bundler group with 8 updates in the /android directory:
2.8.72.9.01.182.01.208.00.112.01.5.01.10.42.14.42.10.22.19.92.10.13.3.03.4.13.4.42.4.13.7.0Updates
addressablefrom 2.8.7 to 2.9.0Changelog
Sourced from addressable's changelog.
Commits
0c3e858Revving version and changelog91915c1Fixing additional vulnerable pathsa091e39Add many more adversarial test cases to ensure we don't have any ReDoS regres...463a819Regenerate gemspec on newer rubygems0afcb0bImprove from O(n^2) to O(n)c87f768Fix a ReDoS vulnerability in URI template matching0d7e9b2Fix links for 2.8.9 in CHANGELOG (#573)e209120Update version, gemspec, and CHANGELOG for 2.8.9 (#572)3875874Reduce gem size by excluding test files (#569)3e57cc6CI: back towindows-2022for MRI jobUpdates
aws-sdk-s3from 1.182.0 to 1.208.0Changelog
Sourced from aws-sdk-s3's changelog.
... (truncated)
Commits
Updates
exconfrom 0.112.0 to 1.5.0Changelog
Sourced from excon's changelog.
... (truncated)
Commits
f59b27ev1.5.0ea89a35expand redirect header redaction (#901)74e1754Raise Excon::Error::InvalidParameter when host is nil instead of crashing wit...4e784d5update bundled certs011b3aev1.4.2aff99fcupdate bundled certscd02b90v1.4.19812664Require cgi/escape instead of cgi (#898)0004103v1.4.0b8debfeAdd SOCKS5 proxy support (#895)Updates
faradayfrom 1.10.4 to 2.14.4Release notes
Sourced from faraday's releases.
... (truncated)
Commits
3ece9bdv2.14.46aa82a5Configure SimpleCov for 1.0, too20d93f8Document Options struct attributes for YARDe7e23aeDefine HTTP verb methods on Faraday so tools can see them9458f04Preserve caller-owned JSON parser optionsb25b1b2Support JSON 3 (#1687)3725183Update copyright year to 2026 (#1683)06bc5adBump actions/checkout from 6 to 7 (#1678)f1ace87Version bump to 2.14.336764bfMerge commit from forkUpdates
jsonfrom 2.10.2 to 2.19.9Release notes
Sourced from json's releases.
... (truncated)
Changelog
Sourced from json's changelog.
... (truncated)
Commits
2cff267Release 2.19.9fd6a65bgenerator.c: don't start with a stack buffer in IO case5233dd9Release 2.19.83f44b26Prevent buffer over-read when generating EOF errorbe8d068Handle invalid types passed asmax_nestingoption59501c0Get rid of all_images gemc7a7b2bAdd a security note in READMEab6c8f2Release 2.19.7f033b9dFix some more edge cases with out of range floats5ca8a67parser.c: Ensure the user provided string can't be mutatedUpdates
jwtfrom 2.10.1 to 3.3.0Changelog
Sourced from jwt's changelog.
... (truncated)
Commits
ccf2489Prepare the v3.3.0 release (#762)6cdacc3Enforce parentheses on method calls with arguments (#761)4a576f8Declutter jwt_spec.rb (#760)7ddcb0aFix the RSA-PSS guard skipping the whole jwt_spec file (#759)7cede0cRefactor JWT::JWK::Set#initialize (#758)6ab1be7Revamp error hierarchy (#722)41fbf31Invalidate the rendered token when detaching the payload (#757)d8e231dReset verification state when replacing the encoded payload (#756)c25fb5eFix JWT::JWK::Set sharing its key collection when copied (#751)bec0ffdIsolate gem builds from release credentials (#755)Updates
rexmlfrom 3.4.1 to 3.4.4Release notes
Sourced from rexml's releases.
... (truncated)
Changelog
Sourced from rexml's changelog.
... (truncated)
Commits
4f32ea3Add 3.4.4 entry (#297)37cde3fAcceptREXML::Document.new("")for backward compatibility (#295)4ffe211Bump version822530cAdd 3.4.3 entry (#293)6ba286cReject no root element XML as an invalid XML (#291)b5b148eThe Zlib::GzipReader in JRuby does not behave as expected with REXML, so the ...1531862Fixed an issue withIOSource#read_untilwhen reaching the end of a file (#288)185bdc7Bump versionf36916fAdd 3.4.2 entry (#284)5859bdeAdded XML declaration check &Source#skip_spacesmethod (#282)Updates
rubyzipfrom 2.4.1 to 3.7.0Release notes
Sourced from rubyzip's releases.
... (truncated)
Changelog
Sourced from rubyzip's changelog.
... (truncated)
Commits
77dfc13Update Changelog for release.d2a9664Document AES encryption in the README.6f57d4dFix AES encryption errors under JRuby.b96b1b4Add tests for AES encryption.8b5b86bEnsure the correct extraction version number is used with Zip64.326765bEnsure entries have the correct compression method when written.a9b2289Wire AES encryption intoOutputStream.4aa008cFixPassThruCompressorto actually encryptSTOREDdata.bdcef49Add stub methods to the parentEncrypterclass.137f678AddAESEncrypterclass.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.