Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump activesupport from 7.0.5 to 7.0.7.2 #7053

Merged
merged 2 commits into from
Sep 20, 2023

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 23, 2023

Bumps activesupport from 7.0.5 to 7.0.7.2.

Release notes

Sourced from activesupport's releases.

7.0.7.2 release

No changes between this and 7.0.7.2. This release was just to fix file permissions in the previous release.

7.0.7.1

Active Support

  • Use a temporary file for storing unencrypted files while editing

    [CVE-2023-38037]

Active Model

  • No changes.

Active Record

  • No changes.

Action View

  • No changes.

Action Pack

  • No changes.

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

... (truncated)

Changelog

Sourced from activesupport's changelog.

Rails 7.0.7.2 (August 22, 2023)

  • No changes.

Rails 7.0.7.1 (August 22, 2023)

  • Use a temporary file for storing unencrypted files while editing

    [CVE-2023-38037]

Rails 7.0.7 (August 09, 2023)

  • Fix Cache::NullStore with local caching for repeated reads.

    fatkodima

  • Fix to_s with no arguments not respecting custom :default formats

    Hartley McGuire

  • Fix ActiveSupport::Inflector.humanize(nil) raising NoMethodError: undefined method `end_with?' for nil:NilClass.

    James Robinson

  • Fix Enumerable#sum for Enumerator#lazy.

    fatkodima, Matthew Draper, Jonathan Hefner

  • Improve error message when EventedFileUpdateChecker is used without a compatible version of the Listen gem

    Hartley McGuire

Rails 7.0.6 (June 29, 2023)

  • Fix EncryptedConfiguration returning incorrect values for some Hash methods

    Hartley McGuire

  • Fix arguments being destructed Enumerable#many? with block.

    Andrew Novoselac

  • Fix humanize for strings ending with id.

    fatkodima

... (truncated)

Commits
  • 3668b4b Preparing for 7.0.7.2 release
  • 2294b8b Bumping version
  • c92caef Preparing for 7.0.7.1 release
  • 936587d updating version / changelog
  • a21d6ed Use a temporary file for storing unencrypted files while editing
  • 522c86f Preparing for 7.0.7 release
  • 5610cba Sync CHANGELOG with the changes in the repository
  • 7e9ffc2 Fix to_s not using :default format with no args
  • a8e88e2 Fix Cache::NullStore with local caching for repeated reads
  • b18b9df Merge pull request #48800 from robinjam/fix-humanize-nil
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot will merge this PR once CI passes on it, as requested by @legobeat.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot bot requested a review from a team as a code owner August 23, 2023 21:44
@dependabot dependabot bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Aug 23, 2023
@codecov-commenter
Copy link

codecov-commenter commented Aug 23, 2023

Codecov Report

Patch and project coverage have no change.

Comparison is base (31744a1) 33.02% compared to head (0bb9c0d) 33.02%.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #7053   +/-   ##
=======================================
  Coverage   33.02%   33.02%           
=======================================
  Files        1004     1004           
  Lines       26888    26888           
  Branches     2131     2131           
=======================================
  Hits         8881     8881           
  Misses      17571    17571           
  Partials      436      436           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@legobeat
Copy link
Contributor

legobeat commented Sep 7, 2023

@dependabot rebase

Bumps [activesupport](https://github.com/rails/rails) from 7.0.5 to 7.0.7.2.
- [Release notes](https://github.com/rails/rails/releases)
- [Changelog](https://github.com/rails/rails/blob/v7.0.7.2/activesupport/CHANGELOG.md)
- [Commits](rails/rails@v7.0.5...v7.0.7.2)

---
updated-dependencies:
- dependency-name: activesupport
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/bundler/activesupport-7.0.7.2 branch from 404d1a5 to cdf07ec Compare September 7, 2023 22:36
Copy link
Contributor

@legobeat legobeat left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot merge

@sethkfman
Copy link
Contributor

@github-actions
Copy link
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@sonarcloud
Copy link

sonarcloud bot commented Sep 15, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Sep 15, 2023

Dependabot tried to merge this PR, but received the following error from GitHub:

Waiting on code owner review from MetaMask/mobile-devs.

Copy link
Contributor

@sethkfman sethkfman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@sethkfman sethkfman added No QA Needed/E2E Only Apply this label when your PR does not need any QA effort. release-7.9.0 labels Sep 20, 2023
@sethkfman sethkfman merged commit 5c7e4ea into main Sep 20, 2023
26 checks passed
@sethkfman sethkfman deleted the dependabot/bundler/activesupport-7.0.7.2 branch September 20, 2023 14:53
@github-actions github-actions bot locked and limited conversation to collaborators Sep 20, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file No QA Needed/E2E Only Apply this label when your PR does not need any QA effort. release-7.9.0 ruby Pull requests that update Ruby code team-security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants