Skip to content

Bump the bundler group across 1 directory with 8 updates - #160

Open
dependabot[bot] wants to merge 1 commit into
developmentfrom
dependabot/bundler/android/bundler-ce4fd0b272
Open

dependabot[bot] wants to merge 1 commit into
developmentfrom
dependabot/bundler/android/bundler-ce4fd0b272

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown

Bumps the bundler group with 8 updates in the /android directory:

Package From To
addressable 2.8.7 2.9.0
aws-sdk-s3 1.182.0 1.208.0
excon 0.112.0 1.5.0
faraday 1.10.4 2.14.4
json 2.10.2 2.19.9
jwt 2.10.1 3.3.0
rexml 3.4.1 3.4.4
rubyzip 2.4.1 3.7.0

Updates addressable from 2.8.7 to 2.9.0

Changelog

Sourced from addressable's changelog.

Addressable 2.9.0

  • fixes ReDoS vulnerability in Addressable::Template#match (fixes incomplete remediation in 2.8.10)

Addressable 2.8.10

  • fixes ReDoS vulnerability in Addressable::Template#match

Addressable 2.8.9

  • Reduce gem size by excluding test files (#569)
  • No need for bundler as development dependency (#571, 5fc1d93)
  • idna/pure: stop building the useless COMPOSITION_TABLE (removes the Addressable::IDNA::COMPOSITION_TABLE constant) (#564)

#569: sporkmonger/addressable#569 #571: sporkmonger/addressable#571 #564: sporkmonger/addressable#564

Addressable 2.8.8

  • Replace the unicode.data blob by a ruby constant (#561)
  • Allow public_suffix 7 (#558)

#561: sporkmonger/addressable#561 #558: sporkmonger/addressable#558

Commits
  • 0c3e858 Revving version and changelog
  • 91915c1 Fixing additional vulnerable paths
  • a091e39 Add many more adversarial test cases to ensure we don't have any ReDoS regres...
  • 463a819 Regenerate gemspec on newer rubygems
  • 0afcb0b Improve from O(n^2) to O(n)
  • c87f768 Fix a ReDoS vulnerability in URI template matching
  • 0d7e9b2 Fix links for 2.8.9 in CHANGELOG (#573)
  • e209120 Update version, gemspec, and CHANGELOG for 2.8.9 (#572)
  • 3875874 Reduce gem size by excluding test files (#569)
  • 3e57cc6 CI: back to windows-2022 for MRI job
  • Additional commits viewable in compare view

Updates aws-sdk-s3 from 1.182.0 to 1.208.0

Changelog

Sourced from aws-sdk-s3's changelog.

1.208.0 (2025-12-16)

  • Feature - Updates to the S3 Encryption Client. The V3 S3 Encryption Client now requires key committing algorithm suites by default.

1.207.0 (2025-12-15)

  • Feature - This release adds support for the new optional field 'LifecycleExpirationDate' in S3 Inventory configurations.

1.206.0 (2025-12-02)

  • Feature - New S3 Storage Class FSX_ONTAP

1.205.0 (2025-11-20)

  • Feature - Enable / Disable ABAC on a general purpose bucket.

1.204.0 (2025-11-19)

  • Feature - Adds support for blocking SSE-C writes to general purpose buckets.

1.203.1 (2025-11-10)

  • Issue - Deprecated :checksum_mode parameter in FileDownloader#download. When set to "DISABLED", a deprecation warning is issued and the parameter is ignored. Use :response_checksum_validation on the S3 client instead to control checksum validation behavior.

1.203.0 (2025-11-05)

  • Feature - Launch IPv6 dual-stack support for S3 Express

1.202.0 (2025-10-28)

  • Feature - Amazon Simple Storage Service / Features: Add conditional writes in CopyObject on destination key to prevent unintended object modifications.

1.201.0 (2025-10-21)

  • Feature - Code Generated Changes, see ./build_tools or aws-sdk-core's CHANGELOG.md for details.

  • Issue - Fix multipart upload to respect request_checksum_calculation when_required mode.

1.200.0 (2025-10-15)

... (truncated)

Commits

Updates excon from 0.112.0 to 1.5.0

Changelog

Sourced from excon's changelog.

1.5.0 2026-05-03

  • update bundled certs
  • invalid parameter error for nil host
  • close security issues around headers and redirect following

1.4.1 2026-03-18

  • change cgi require to cgi/escape for ruby 4.0+

1.4.0 2026-03-02

  • fixes for ruby4
  • add ruby 4.0 and drop 3.2 from ci
  • add user-configurable global resolver factory
  • add SOCK5 proxy support

1.3.2 2025-12-03

  • update bundled certs

1.3.1 2025-11-05

  • update bundled certs

1.3.0 2025-08-18

  • proxy connect should always include port, regardless of default

1.2.9 2025-08-15

  • bump actions/checkout
  • update bundled certs

1.2.8 2025-07-16

  • update bundled certs

1.2.7 2025-05-27

  • freezes caused inadvertent breaking changes, so partially rolling back

... (truncated)

Commits

Updates faraday from 1.10.4 to 2.14.4

Release notes

Sourced from faraday's releases.

v2.14.4

What's Changed

New Contributors

Full Changelog: lostisland/faraday@v2.14.3...v2.14.4

v2.14.3

Security Note

This release contains a security fix, we recommend all users to upgrade as soon as possible. A Security Advisory with more details will be posted shortly.

What's Changed

New Contributors

Full Changelog: lostisland/faraday@v2.14.2...v2.14.3

v2.14.2

Security Note

This release contains a security fix, we recommend all users to upgrade as soon as possible. A Security Advisory with more details will be posted shortly.

What's Changed

New Contributors

Full Changelog: lostisland/faraday@v2.14.1...v2.14.2

... (truncated)

Commits

Updates json from 2.10.2 to 2.19.9

Release notes

Sourced from json's releases.

v2.19.9

  • Fix buffer overflow that could lead to a crash when writing JSON directly into an IO with JSON.generate(object, io). [CVE-2026-54696].

Full Changelog: ruby/json@v2.19.8...v2.19.9

v2.19.8

What's Changed

  • Fix 1-byte buffer overread on EOS errors.
  • Handle invalid types passed as max_nesting option.

Full Changelog: ruby/json@v2.19.7...v2.19.8

v2.19.7

What's Changed

  • Fix some more edge cases with out of range floats.
  • Ensure the string provided to JSON.parse can't be mutated during parsing.
  • Add missing write barriers in State#dup.
  • Further validate generator depth config.

Full Changelog: ruby/json@v2.19.6...v2.19.7

v2.19.6

What's Changed

  • Cleanly handle overly large depth generator argument.
  • Add missing write barrier in ParserConfig.

Full Changelog: ruby/json@v2.19.5...v2.19.6

v2.19.5

What's Changed

  • Cap the parser to emit a maximum of 5 deprecation warnings per document. Emitting more is not helpful.

Full Changelog: ruby/json@v2.19.4...v2.19.5

v2.19.4

What's Changed

  • Fix parsing of out of range floats (very large exponents that lead to either 0.0 or Inf).

Full Changelog: ruby/json@v2.19.2...v2.19.4

v2.19.3

  • Fix handling of unescaped control characters preceeded by a backslash.

Full Changelog: ruby/json@v2.19.2...v2.19.3

... (truncated)

Changelog

Sourced from json's changelog.

2026-06-11 (2.19.9)

  • Fix buffer overflow that could lead to a crash when writing JSON directly into an IO with JSON.generate(object, io). [CVE-2026-54696].

2026-06-03 (2.19.8)

  • Fix 1-byte buffer overread on EOS errors.
  • Handle invalid types passed as max_nesting option.

2026-05-28 (2.19.7)

  • Fix some more edge cases with out of range floats.
  • Ensure the string provided to JSON.parse can't be mutated during parsing.
  • Add missing write barriers in State#dup.
  • Further validate generator depth config.

2026-05-28 (2.19.6)

  • Cleanly handle overly large depth generator argument.
  • Add missing write barrier in ParserConfig.

2026-05-04 (2.19.5)

  • Cap the parser to emit a maximum of 5 deprecation warnings per document. Emitting more is not helpful.

2026-04-19 (2.19.4)

  • Fix parsing of out of range floats (very large exponents that lead to either 0.0 or Inf).

2026-03-25 (2.19.3)

  • Fix handling of unescaped control characters preceeded by a backslash.

2026-03-18 (2.19.2)

  • Fix a format string injection vulnerability in JSON.parse(doc, allow_duplicate_key: false). CVE-2026-33210.

2026-03-08 (2.19.1)

  • Fix a compiler dependent GC bug introduced in 2.18.0.

2026-03-06 (2.19.0)

  • Fix allow_blank parsing option to no longer allow invalid types (e.g. load([], allow_blank: true) now raise a type error).
  • Add allow_invalid_escape parsing option to ignore backslashes that aren't followed by one of the valid escape characters.

2026-02-03 (2.18.1)

  • Fix a potential crash in very specific circumstance if GC triggers during a call to to_json

... (truncated)

Commits
  • 2cff267 Release 2.19.9
  • fd6a65b generator.c: don't start with a stack buffer in IO case
  • 5233dd9 Release 2.19.8
  • 3f44b26 Prevent buffer over-read when generating EOF error
  • be8d068 Handle invalid types passed as max_nesting option
  • 59501c0 Get rid of all_images gem
  • c7a7b2b Add a security note in README
  • ab6c8f2 Release 2.19.7
  • f033b9d Fix some more edge cases with out of range floats
  • 5ca8a67 parser.c: Ensure the user provided string can't be mutated
  • Additional commits viewable in compare view

Updates jwt from 2.10.1 to 3.3.0

Changelog

Sourced from jwt's changelog.

v3.3.0 (2026-09-11)

Full Changelog

Features:

Fixes and enhancements:

  • Refactor JWT::JWK::Set#initialize so each construction path is a named method #758 (@​anakinj)
  • Fix rejection of unknown algorithms from JWKs for RFC compliance and pquip #728
  • Fix the Style/DirectiveScope RuboCop offense failing the build #752
  • Fix JWT::JWK::Set sharing its key collection with the set it was copied from #751
  • Reset the decoded payload and verification state in JWT::EncodedToken#encoded_payload= #749
  • Fix JWT::Token#detach_payload! not invalidating an already rendered token #748

v3.2.0 (2026-05-13)

Full Changelog

Features:

  • Add enforce_hmac_key_length configuration option #716 - (@​304)

Fixes and enhancements:

v3.1.2 (2025-06-28)

Full Changelog

Fixes and enhancements:

  • Avoid using the same digest across calls in JWT::JWA::Ecdsa and JWT::JWA::Rsa #697
  • Fix signing with a EC JWK #699 (@​anakinj)

v3.1.1 (2025-06-24)

Full Changelog

Fixes and enhancements:

  • Require the algorithm to be provided when signing and verifying tokens using JWKs #695 (@​anakinj)

... (truncated)

Commits
  • ccf2489 Prepare the v3.3.0 release (#762)
  • 6cdacc3 Enforce parentheses on method calls with arguments (#761)
  • 4a576f8 Declutter jwt_spec.rb (#760)
  • 7ddcb0a Fix the RSA-PSS guard skipping the whole jwt_spec file (#759)
  • 7cede0c Refactor JWT::JWK::Set#initialize (#758)
  • 6ab1be7 Revamp error hierarchy (#722)
  • 41fbf31 Invalidate the rendered token when detaching the payload (#757)
  • d8e231d Reset verification state when replacing the encoded payload (#756)
  • c25fb5e Fix JWT::JWK::Set sharing its key collection when copied (#751)
  • bec0ffd Isolate gem builds from release credentials (#755)
  • Additional commits viewable in compare view

Updates rexml from 3.4.1 to 3.4.4

Release notes

Sourced from rexml's releases.

REXML 3.4.4 - 2025-09-10

Improvement

  • Accept REXML::Document.new("") for backward compatibility
    • GH-296
    • GH-295
    • Patch by NAITOH Jun
    • Reported by Joe Rafaniello

Thanks

  • NAITOH Jun

  • Joe Rafaniello

REXML 3.4.3 - 2025-09-07

Improvement

  • Reject no root element XML as an invalid XML
    • GH-289
    • GH-291
    • Patch by NAITOH Jun
    • Reported by Sutou Kouhei

Fixes

  • Fixed an issue with IOSource#read_until when reaching the end of a file
    • GH-287
    • GH-288
    • Patch by NAITOH Jun
    • Reported by Jason Thomas

Thanks

  • NAITOH Jun

  • Sutou Kouhei

  • Jason Thomas

REXML 3.4.2 - 2025-08-26

Improvement

... (truncated)

Changelog

Sourced from rexml's changelog.

3.4.4 - 2025-09-10 {#version-3-4-4}

Improvement

  • Accept REXML::Document.new("") for backward compatibility
    • GH-296
    • GH-295
    • Patch by NAITOH Jun
    • Reported by Joe Rafaniello

Thanks

  • NAITOH Jun

  • Joe Rafaniello

3.4.3 - 2025-09-07 {#version-3-4-3}

Improvement

  • Reject no root element XML as an invalid XML
    • GH-289
    • GH-291
    • Patch by NAITOH Jun
    • Reported by Sutou Kouhei

Fixes

  • Fixed an issue with IOSource#read_until when reaching the end of a file
    • GH-287
    • GH-288
    • Patch by NAITOH Jun
    • Reported by Jason Thomas

Thanks

  • NAITOH Jun

  • Sutou Kouhei

  • Jason Thomas

3.4.2 - 2025-08-26 {#version-3-4-2}

Improvement

... (truncated)

Commits
  • 4f32ea3 Add 3.4.4 entry (#297)
  • 37cde3f Accept REXML::Document.new("") for backward compatibility (#295)
  • 4ffe211 Bump version
  • 822530c Add 3.4.3 entry (#293)
  • 6ba286c Reject no root element XML as an invalid XML (#291)
  • b5b148e The Zlib::GzipReader in JRuby does not behave as expected with REXML, so the ...
  • 1531862 Fixed an issue with IOSource#read_until when reaching the end of a file (#288)
  • 185bdc7 Bump version
  • f36916f Add 3.4.2 entry (#284)
  • 5859bde Added XML declaration check & Source#skip_spaces method (#282)
  • Additional commits viewable in compare view

Updates rubyzip from 2.4.1 to 3.7.0

Release notes

Sourced from rubyzip's releases.

v3.7.0

Version 3.7.0

The 3.7.x line adds AES encryption; bulk adding and extraction of entries, and; supports setting the encoding of an InputStream. See README.md for details.

⚠️ There are breaking changes in the 3.x series ⚠️

Please see the README and Updating to version 3.x in the wiki for help upgrading from version 2.4.x to version 3.x.

v3.6.0

Version 3.6.0

The 3.6.x line lazy-loads OpenSSL only when really needed (for faster start-up times) and clamps internal (DOS-based) dates and times to the allowed range. See README.md for details.

⚠️ There are breaking changes in the 3.x series ⚠️

Please see the README and Updating to version 3.x in the wiki for help upgrading from version 2.4.x to version 3.x.

v3.5.0

Version 3.5.0

The 3.5.x line adds the ability to set a Decrypter per-Entry as opposed to only per-InputStream. See README.md for details.

⚠️ There are breaking changes in the 3.x series ⚠️

Please see the README and Updating to version 3.x in the wiki for help upgrading from version 2.4.x to version 3.x.

v3.4.1

Version 3.4.1

The 3.4.x line adds lib/rubyzip.rb to make including rubyzip in your Gemfile easier. See README.md for details.

⚠️ There are breaking changes in the 3.x series ⚠️

Please see the README and Updating to version 3.x in the wiki for help upgrading from version 2.4.x to version 3.x.

v3.4.0

Version 3.4.0

3.4.0 adds lib/rubyzip.rb to make including rubyzip in your Gemfile easier. See README.md for details.

⚠️ There are breaking changes in the 3.x series ⚠️

Please see the README and Updating to version 3.x in the wiki for help upgrading from version 2.4.x to version 3.x.

v3.3.1

Version 3.3.1

The 3.3.x line ensures that Zip::InputStream behaves more like standard Ruby IO classes.

... (truncated)

Changelog

Sourced from rubyzip's changelog.

3.7.0 (2026-09-18)

  • Add AES Encryption. #678
  • Add methods to Zip::File for bulk adding and extraction of entries. #679
  • Support setting the encoding of an InputStream. #668

Tooling/internal:

  • Add an AGENTS.md for those using such.
  • Attempt to fix transient failures in encryption tests.

3.6.0 (2026-09-01)

  • Forward options from OutputStream.open without a block. #674
  • Clamp DOS date and time to the range the fields can hold. #671

Tooling/internal:

  • Unix owner ids no longer default to 0 (root).
  • Legacy Unix owner ids no longer default to 0 (root).
  • Handle short reads in copy_stream_n. #675
  • Retain required Zip64 offset fields. #676
  • Load openssl only when AES encryption is used. #672

3.5.0 (2026-08-18)

  • Fix the link to Ruby doc in README to the latest version. #670
  • Support passing decrypter to encrypted entry via get_input_stream. #667

3.4.1 (2026-06-27)

  • Fixed DecryptedIo to only perform integrity once. #665

3.4.0 (2026-06-14)

  • Prevent entries from being extracted outside specified directory. #664. Thanks to @​connorshea for additional reporting on this.
  • Use SecureRandom in place of insecure Random.
  • Stop reading the central directory on first error.
  • Add a check on number of declared entries in a zip file. Thanks to @​connorshea for reporting this.
  • Add note to README re reporting security issues privately.
  • Add lib/rubyzip.rb for Bundler auto-require. #660

Tooling/internal:

  • Replace the test Excel spreadsheet fixture.
  • Use assert_silent shorthand when expecting no output from a test.
  • Clean up CentralDirectory instance variables.
  • Add Ruby 4.0 to the Windows CI and update CI matrix in the README.
  • List ZIP docs that we store here and link to online versions. #657

... (truncated)

Commits
  • 77dfc13 Update Changelog for release.
  • d2a9664 Document AES encryption in the README.
  • 6f57d4d Fix AES encryption errors under JRuby.
  • b96b1b4 Add tests for AES encryption.
  • 8b5b86b Ensure the correct extraction version number is used with Zip64.
  • 326765b Ensure entries have the correct compression method when written.
  • a9b2289 Wire AES encryption into OutputStream.
  • 4aa008c Fix PassThruCompressor to actually encrypt STORED data.
  • bdcef49 Add stub methods to the parent Encrypter class.
  • 137f678 Add AESEncrypter class.
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the bundler group with 8 updates in the /android directory:

| Package | From | To |
| --- | --- | --- |
| [addressable](https://github.com/sporkmonger/addressable) | `2.8.7` | `2.9.0` |
| [aws-sdk-s3](https://github.com/aws/aws-sdk-ruby) | `1.182.0` | `1.208.0` |
| [excon](https://github.com/excon/excon) | `0.112.0` | `1.5.0` |
| [faraday](https://github.com/lostisland/faraday) | `1.10.4` | `2.14.4` |
| [json](https://github.com/ruby/json) | `2.10.2` | `2.19.9` |
| [jwt](https://github.com/jwt/ruby-jwt) | `2.10.1` | `3.3.0` |
| [rexml](https://github.com/ruby/rexml) | `3.4.1` | `3.4.4` |
| [rubyzip](https://github.com/rubyzip/rubyzip) | `2.4.1` | `3.7.0` |



Updates `addressable` from 2.8.7 to 2.9.0
- [Changelog](https://github.com/sporkmonger/addressable/blob/main/CHANGELOG.md)
- [Commits](sporkmonger/addressable@addressable-2.8.7...addressable-2.9.0)

Updates `aws-sdk-s3` from 1.182.0 to 1.208.0
- [Release notes](https://github.com/aws/aws-sdk-ruby/releases)
- [Changelog](https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sdk-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-ruby/commits)

Updates `excon` from 0.112.0 to 1.5.0
- [Changelog](https://github.com/excon/excon/blob/master/changelog.txt)
- [Commits](excon/excon@v0.112.0...v1.5.0)

Updates `faraday` from 1.10.4 to 2.14.4
- [Release notes](https://github.com/lostisland/faraday/releases)
- [Changelog](https://github.com/lostisland/faraday/blob/main/CHANGELOG.md)
- [Commits](lostisland/faraday@v1.10.4...v2.14.4)

Updates `json` from 2.10.2 to 2.19.9
- [Release notes](https://github.com/ruby/json/releases)
- [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md)
- [Commits](ruby/json@v2.10.2...v2.19.9)

Updates `jwt` from 2.10.1 to 3.3.0
- [Release notes](https://github.com/jwt/ruby-jwt/releases)
- [Changelog](https://github.com/jwt/ruby-jwt/blob/main/CHANGELOG.md)
- [Commits](jwt/ruby-jwt@v2.10.1...v3.3.0)

Updates `rexml` from 3.4.1 to 3.4.4
- [Release notes](https://github.com/ruby/rexml/releases)
- [Changelog](https://github.com/ruby/rexml/blob/master/NEWS.md)
- [Commits](ruby/rexml@v3.4.1...v3.4.4)

Updates `rubyzip` from 2.4.1 to 3.7.0
- [Release notes](https://github.com/rubyzip/rubyzip/releases)
- [Changelog](https://github.com/rubyzip/rubyzip/blob/main/Changelog.md)
- [Commits](rubyzip/rubyzip@v2.4.1...v3.7.0)

---
updated-dependencies:
- dependency-name: addressable
  dependency-version: 2.9.0
  dependency-type: indirect
  dependency-group: bundler
- dependency-name: aws-sdk-s3
  dependency-version: 1.208.0
  dependency-type: indirect
  dependency-group: bundler
- dependency-name: excon
  dependency-version: 1.5.0
  dependency-type: indirect
  dependency-group: bundler
- dependency-name: faraday
  dependency-version: 2.14.4
  dependency-type: indirect
  dependency-group: bundler
- dependency-name: json
  dependency-version: 2.19.9
  dependency-type: indirect
  dependency-group: bundler
- dependency-name: jwt
  dependency-version: 3.3.0
  dependency-type: indirect
  dependency-group: bundler
- dependency-name: rexml
  dependency-version: 3.4.4
  dependency-type: indirect
  dependency-group: bundler
- dependency-name: rubyzip
  dependency-version: 3.7.0
  dependency-type: indirect
  dependency-group: bundler
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants