Update brakeman requirement from ~> 6.1 to ~> 8.0#5
Conversation
Updates the requirements on [brakeman](https://github.com/presidentbeef/brakeman) to permit the latest version. - [Release notes](https://github.com/presidentbeef/brakeman/releases) - [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md) - [Commits](presidentbeef/brakeman@v6.2.2...v8.0.2) --- updated-dependencies: - dependency-name: brakeman dependency-version: 8.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
Superseded by a single consolidated |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…isories Supersede 5 stale Dependabot PRs (#2,#4,#5,#6,#7) whose targets lagged current releases by ~4 months, via one full bundle update. Clears all 21 bundler-audit advisories. Runtime: async 2.35.3->2.39.0, async-http 0.94.0->0.95.1, protocol-http 0.58.0->0.62.2, aws-sdk-core 3.241.4->3.250.0. Security: rack 3.2.4->3.2.6, json 2.18.0->2.19.7, addressable 2.8.8->2.9.0, activesupport 8.1.2->8.1.3 (dev/test-only except json via async->console). Widen brakeman dev-dep ~> 6.1 -> ~> 8.0 (folds in Dependabot #5). Group the socketry async stack, aws-sdk, and rubocop gems in dependabot.yml (async-http pins its protocol-*/io-* stack, so they must move together); this edit also re-wakes Dependabot, paused after ~113 days of inactivity. bin/ci green: rufo, rubocop, rspec (84 unit + 17 docker integration), bundler-audit clean.
Updates the requirements on brakeman to permit the latest version.
Release notes
Sourced from brakeman's releases.
... (truncated)
Changelog
Sourced from brakeman's changelog.
... (truncated)
Commits
c072892Bump to 8.0.2b3ad4c8Merge pull request #2007 from presidentbeef/add_ruby_4_0_to_tests0fb669aAdd Ruby 4.0 to test matrixc531af9Merge pull request #2006 from presidentbeef/set_reline_to_use_stderr3028a07Use correct output destination with Relinea0cbbc9Merge pull request #2004 from imran-iq/imran/push-rpwxzowkpovkbfbc5c9Fix argument error to logger.cleanup406e8f1Bump to 8.0.16d37b1cMerge pull request #2002 from presidentbeef/always_quit192fcb9Make sure to quit after runningDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)