Skip to content

Bump brakeman from 8.0.2 to 8.0.4#11

Open
dependabot[bot] wants to merge 29 commits into
mainfrom
dependabot/bundler/brakeman-8.0.4
Open

Bump brakeman from 8.0.2 to 8.0.4#11
dependabot[bot] wants to merge 29 commits into
mainfrom
dependabot/bundler/brakeman-8.0.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 3, 2026

Copy link
Copy Markdown

Bumps brakeman from 8.0.2 to 8.0.4.

Release notes

Sourced from brakeman's releases.

8.0.3

  • Add release age option for --ensure-latest (#1989)
  • Fix polymorphic_name SQLi false positive (Fredrico Franco)
  • Fix logger behavior when loading config files (#2009)
  • Handle application names with module prefixes (#2011)
Changelog

Sourced from brakeman's changelog.

8.0.4 - 2026-02-26

  • Load 'date' library for --ensure-latest

8.0.3 - 2026-02-26

  • Fix polymorphic_name SQLi false positive (Fredrico Franco)
  • Fix logger behavior when loading config files
  • Handle application names with module prefixes
  • Add release age option for --ensure-latest
Commits
  • 2e55d45 Bump to 8.0.4
  • d6c6c9a Merge pull request #2016 from presidentbeef/fix-ensure-latest-date
  • 56f9324 Load 'date' for --ensure-latest
  • 8b644a6 Bump to 8.0.3
  • 08e0a18 Update CHANGES
  • a29fe44 Merge pull request #2014 from FFederi/fix-polymorphic-name-false-positive
  • 61150cf Fix polymorphic_name false positive
  • f65d077 Merge pull request #2013 from presidentbeef/better_logger_loading_options
  • c5dcda5 Fix logger behavior when loading config files
  • c1d7ccc Merge pull request #2012 from presidentbeef/handle_application_config_better
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

sansari and others added 29 commits February 10, 2026 15:19
- Enable PWA routes (manifest + service worker)
- Fix manifest: add short_name, proper theme/background colors
- Activate minimal service worker for PWA qualification
- Add badge Stimulus controller: fetches dashboard JSON, calls
  navigator.setAppBadge() with overdue + due_soon count, polls
  every 5 min, updates on visibilitychange
- Add notification permission banner for iOS badge support
- Create CHANGELOG.md with project history
- Create AGENTS.md with notes for future Claude Code sessions

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Create plans/ directory with reconstructed plans for all 6 major
  phases of the project (001-initial-build through 006-documentation-workflow)
- Update CHANGELOG.md to reference plan files in each entry
- Update SPEC.md to reflect current app behavior (2-week window,
  log page, PWA support, Railway deployment details)
- Add Documentation Workflow section to CLAUDE.md establishing
  conventions: plans committed to repo, changelog references plans,
  spec stays in sync, CLAUDE.md documents workflow

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Server-side push via web-push gem with VAPID auth. BadgeNotificationJob
runs every 12 hours, sends push when task count changes. Service worker
updates badge even when app is closed. Job self-reports failures via push.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Entrypoint checked last 2 args but CMD has 4 args, so db:prepare
never ran on deploy. Now checks first 2 args ($1, $2) instead.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Priority was unused and not meaningful. Drop the column, remove validation,
helper, view references, and tests.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Add a green "Done" button to each task row on the dashboard and a
"Mark Done" button on the task detail page. Both use the existing
POST /tasks/:id/complete endpoint with a Turbo confirmation dialog.
The complete action now uses redirect_back so clicking Done from the
dashboard returns to the dashboard instead of navigating away.

https://claude.ai/code/session_01Ta8kLsYYDH1xYJaiQvBmN2
Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
- Fix RuboCop Layout/SpaceInsideArrayLiteralBrackets errors by removing spaces inside array brackets
- Fix test failures by using dig() to safely access VAPID credentials that may not be set in test environment

Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
- Add spaces inside array brackets per rubocop-rails-omakase style guide
- Changed [:foo] to [ :foo ] in 4 controller files

Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
…ty line

- Disable Layout/SpaceInsideArrayLiteralBrackets in .rubocop.yml
- Remove extra empty line before class end in maintenance_task_test.rb

Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
Bumps [brakeman](https://github.com/presidentbeef/brakeman) from 8.0.2 to 8.0.4.
- [Release notes](https://github.com/presidentbeef/brakeman/releases)
- [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md)
- [Commits](presidentbeef/brakeman@v8.0.2...v8.0.4)

---
updated-dependencies:
- dependency-name: brakeman
  dependency-version: 8.0.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Mar 3, 2026
@dependabot dependabot Bot added ruby Pull requests that update ruby code dependencies Pull requests that update a dependency file labels Mar 3, 2026
@sansari
sansari force-pushed the main branch 2 times, most recently from cb219e1 to 695229c Compare June 25, 2026 06:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants