🚨 [security] Update rubocop-rails 2.25.1 → 2.26.0 (minor) #1344
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ rubocop-rails (2.25.1 → 2.26.0) · Repo · Changelog
Release Notes
2.26.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 47 commits:
Cut 2.26.0
Update Changelog
Merge pull request #1337 from Earlopain/validation-error
Merge pull request #1336 from koic/add_new_rails_enum_syntax_cop
Merge pull request #1309 from ytjmt/support-new-enum-syntax-for-enum-hash-cop
[Fix #1238] Add new `Rails/EnumSyntax` cop
Merge pull request #1335 from Earlopain/error-bulk-change-table
Fix an error for `Rails/Validation` when passing no arguments
Update `Rails/Validation` specs to modern style
Merge pull request #1334 from Earlopain/cop-registry-deprecated
Fix an error for `Rails/BulkChangeTable` when the block for `change_table` is empty
Don't use deprecated `Cop.registry` in specs
Update a changelog file name
Merge pull request #1003 from r7kamura/root-pathname-methods-index
Merge pull request #1323 from Earlopain/where-equal-not
[Fix #1199] Make `Rails/WhereEquals` aware of `where.not(...)`
Merge pull request #1330 from Earlopain/where-not-error
Fix an error for `Rails/WhereNot` without second argument
Merge pull request #1325 from Earlopain/render-plain-text-error
Fix an error for `Rails/RenderPlainText` when the content type is passed as a constant
Merge pull request #1321 from Earlopain/where-equal-error
Fix an error for `Style/WhereEquals` when the second argument is not yet typed
Merge pull request #1320 from Earlopain/rails-version-redundant-presence-validation
[Fix #1319] Fix false positive for `RedundantPresenceValidationOnBelongsTo`
Merge pull request #1316 from Uaitt/documentation-typo
Correct typo in Rails/WhereEquals documentation
Merge pull request #1311 from tldn0718/fix-false-negatives-for-action-controller-flash-before-render
Merge pull request #1302 from koic/make_style_collection_compact_aware_of_params
Allow `params` receiver by default for `Style/CollectionMethods`
Merge pull request #1314 from biow0lf/fix-docs
Use right ticks
Merge pull request #1313 from koic/fix_false_positive_for_rails_compact_blank
Fix false positives for `Rails/CompactBlank`
Merge pull request #1310 from fatkodima/compact_blank-select_present
Support Rails 7 syntax for Rails/EnumHash cop
Fix false negatives for implicit render or rescue blocks
Change `Rails/CompactBlank` to handle `select(&:present?)`
Merge pull request #1307 from padarom/fix-pluck-in-where-documentation
Suppress RuboCop offenses
Clarify the wording of the `Rails/PluckInWhere` cop
Merge pull request #1298 from ytjmt/support-new-enum-syntax-for-enum-uniqueness-cop
Suppress RuboCop offense
Merge pull request #1306 from Earlopain/pluralization-grammar-byte
Make `Rails/PluralizationGrammar` aware of byte methods
Merge pull request #1304 from fatkodima/ignored_skip_action_filter_option-multiple-callbacks
Change `Rails/IgnoredSkipActionFilterOption` to handle multiple callbacks
Switch back docs version to master
Release Notes
5.25.1 (from changelog)
5.25.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 24 commits:
prepped for release
- Fix incompatibility caused by minitest-hooks & rails invading minitest internals.
- Revert change from =~ to match? to allow for nil if $TERM undefined.
prepped for release
+ Refactored siginfo handler to reduce runtime costs. Saved ~30%!
normalized all actual/expected var names for assert_equal tests
Accept colon style Hash#inspect in test. (tompng)
- Improve description of test:slow task. (stomar)
- Cleaning up ancient code checking for defined?(Encoding) and the like.
Minor fix to make deprecation tests pass when using rake testW0
oops
+ Fixed some inefficiencies filtering and matching (mostly backtraces).
More foolish consistency...
More foolish consistency... "So many parens!" edition
More foolish consistency...
"A foolish consistency is the hobgoblin of little minds, adored by little statesmen and philosophers and divines"—Emerson
- Disambiguated some shadowed variables in minitest/compress.
Got rid of ANCIENT pre-Integer-merge tests
Got rid of ANCIENT RUBY18 conditioned tests
- Fixed an ironic bug if using string-literals AND Werror.
Finally removed all clean + heredoc for squiggly heredocs in test.
- Added missing rdoc to get back to 100% coverage.
Double quoted some (ancient) string literals.
Fixed 3 tests when using minitest-gcstats.
Commits
See the full diff on Github. The new version differs by 3 commits:
v1.26.3
Merge pull request #351 from y-yagi/ensure_not_to_use_old_concurrent-ruby
Ensure not to use old `concurrent-ruby`
Security Advisories 🚨
🚨 REXML denial of service vulnerability
Release Notes
3.3.6
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 15 commits:
Add 3.3.6 entry
parser tree: improve namespace conflicted attribute check performance
Fix a bug that Stream parser doesn't expand the user-defined entity references for "text" (#200)
parser: keep the current namespaces instead of stack of Set
parser: move duplicated end tag check to BaseParser
test tree-parser: move common method to base class
test: fix indent
test: fix indent
Use loop instead of recursive call for Element#namespace
Use loop instead of recursive call for Element#root
test: split duplicated attribute case and namespace conflict case
Fix to not allow parameter entity references at internal subsets (#191)
Fix RuntimeError in `REXML::Parsers::BaseParser` for valid feeds (#199)
Improve `BaseParser#unnormalize` (#194)
Bump version
Release Notes
1.32.1 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 6 commits:
Cut 1.32.1
Update Changelog
Mark `RuboCop::AST::EnsureNode` as being in a void context.
Fix readme CI badge (#308)
Move test `Node#used?` predicate method definition
Restore docs/antora.yml
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase
.All Depfu comment commands