Skip to content

Bump the bundler group across 1 directory with 17 updates - #1449

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/bundler-5ac79145f6
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/bundler-5ac79145f6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the bundler group with 17 updates in the / directory:

Package From To
aws-sdk-s3 1.228.1 1.232.1
bootsnap 1.24.6 1.26.0
devise 4.9.4 5.0.4
devise_token_auth 1.2.6 1.3.0
good_job 4.19.2 4.19.3
newrelic_rpm 10.6.0 10.8.0
pagy 43.6.1 43.6.2
annotaterb 4.24.0 4.25.0
brakeman 8.0.5 8.0.6
rubocop 1.88.2 1.91.0
rubocop-performance 1.26.1 1.27.0
rubocop-rails 2.36.0 2.38.0
parallel_tests 5.7.0 5.8.0
pg_query 6.2.2 6.2.3
rspec-openapi 0.31.0 0.34.0
selenium-webdriver 4.46.0 4.49.0
webmock 3.26.2 3.26.4

Updates aws-sdk-s3 from 1.228.1 to 1.232.1

Changelog

Sourced from aws-sdk-s3's changelog.

1.232.1 (2026-09-16)

  • Issue - Return the copy response from multipart copy_to/copy_from instead of nil on success.

1.232.0 (2026-09-11)

  • Feature - Updated S3 Object Lock Default Retention documentation.

1.231.0 (2026-09-09)

  • Feature - Code Generated Changes, see ./build_tools or aws-sdk-core's CHANGELOG.md for details.

1.230.0 (2026-09-08)

  • Feature - Adds support for Amazon S3 Object Lock variable retention. Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level.

1.229.0 (2026-08-06)

  • Feature - AWS Backup now lets you create read-only access points for Amazon S3 recovery points, enabling you to access backup data using S3 APIs without initiating a restore.

1.228.2 (2026-07-30)

  • Issue - S3 Encryption Client, encryptionV2 and encryptionV3, returns a decryption error for a malformed material description.
Commits

Updates bootsnap from 1.24.6 to 1.26.0

Release notes

Sourced from bootsnap's releases.

v1.26.0

What's Changed

  • Handle top level Coverage constant being defined, but without it being the true stdlib coverage module.
  • Fix bootsnap precompile that could generate a corrupted cache entry if an already cached YAML file was modified without changing its size.
  • Workaround a potential Ruby SEGV if Bootsnap.instrumentation raised an error.

v1.25.0

What's Changed

  • Improve YAML parsing cache to more efficiently handle Time, Date and DateTime.

  • Don't invalidate the compile cache when YJIT is toggled. YJIT is a runtime JIT and doesn't change the serialized instruction sequences that are cached, but enabling it (via --yjit, RUBYOPT, or RubyVM::YJIT.enable) adds a +YJIT marker to RUBY_DESCRIPTION ( +YJIT <token> on YJIT_SUPPORT builds), which is part of the cache key. This previously discarded the entire compile cache whenever YJIT was enabled at runtime but not at precompile time (or vice versa). The marker is now stripped before hashing.

  • Fix CompileCache::Native.fetch and .precompile reading a non-String path argument (e.g. a Pathname) with RSTRING_PTR. Regression from 1.24.0.

Full Changelog: rails/bootsnap@v1.24.6...v1.25.0

Changelog

Sourced from bootsnap's changelog.

1.26.0

  • Handle top level Coverage constant being defined, but without it being the true stdlib coverage module.
  • Fix bootsnap precompile that could generate a corrupted cache entry if an already cached YAML file was modified without changing its size.
  • Workaround a potential Ruby SEGV if Bootsnap.instrumentation raised an error.

1.25.0

  • Improve YAML parsing cache to more efficiently handle Time, Date and DateTime.

  • Don't invalidate the compile cache when YJIT is toggled. YJIT is a runtime JIT and doesn't change the serialized instruction sequences that are cached, but enabling it (via --yjit, RUBYOPT, or RubyVM::YJIT.enable) adds a +YJIT marker to RUBY_DESCRIPTION ( +YJIT <token> on YJIT_SUPPORT builds), which is part of the cache key. This previously discarded the entire compile cache whenever YJIT was enabled at runtime but not at precompile time (or vice versa). The marker is now stripped before hashing.

  • Fix CompileCache::Native.fetch and .precompile reading a non-String path argument (e.g. a Pathname) with RSTRING_PTR. Regression from 1.24.0.

Commits
  • 67a7290 Release 1.26.0
  • 1881b9a Merge pull request #573 from byroot/same-size-miscompilation
  • 605bbeb Fix precompilation when regenerating an existing cache entry of the same size
  • 5fd59da Merge pull request #569 from OskarEichler/codex/accept-tempfile-fd-zero
  • 70550c7 Merge pull request #568 from OskarEichler/codex/remove-umask-debug-output
  • 8aed2ed Accept tempfile descriptor zero
  • f7457ea Remove umask debug output
  • 9ee62a2 Merge pull request #567 from byroot/rename-mod
  • 7c8178e Handle write(2) being interrupted.
  • 3e755ca atomic_write_cache_file: stop leaking FD on error
  • Additional commits viewable in compare view

Updates devise from 4.9.4 to 5.0.4

Release notes

Sourced from devise's releases.

v5.0.4

https://github.com/heartcombo/devise/blob/v5.0.4/CHANGELOG.md#504---2026-05-08

v5.0.3

https://github.com/heartcombo/devise/blob/v5.0.3/CHANGELOG.md#503---2026-03-16

v5.0.2

https://github.com/heartcombo/devise/blob/v5.0.2/CHANGELOG.md#502---2026-02-18

v5.0.1

https://github.com/heartcombo/devise/blob/v5.0.1/CHANGELOG.md#501---2026-02-13

v5.0.0

https://github.com/heartcombo/devise/blob/v5.0.0/CHANGELOG.md#500---2026-01-23

v5.0.0.rc

https://github.com/heartcombo/devise/blob/v5.0.0.rc/CHANGELOG.md#500rc---2025-12-31

Changelog

Sourced from devise's changelog.

5.0.4 - 2026-05-08

5.0.3 - 2026-03-16

5.0.2 - 2026-02-18

  • enhancements
    • Allow resource class scopes to override the global configuration for sign_in_after_change_password behaviour. #5825
      • Note: some users ran into an issue with this change because RegistrationsController now relies on a setting from the :registerable module. These users were configuring their own routes pointing to the RegistrationsController for resource edit/update actions mostly, without relying on the other registration actions (e.g. user sign up.), so they omitted :registerable from the model declaration. While using just a portion of the controller functionality is a valid use for :registerable (or any module really), the module must still be declared in the model, much like the other modules must be declared if you plan on using just a portion of their behavior. Please check this issue for more info.
    • Add sign_in_after_reset_password? check hook to passwords controller, to allow it to be customized by users. #5826

5.0.1 - 2026-02-13

  • bug fixes
    • Fix translation issue with German E-Mail on invalid authentication messages caused by previous fix for incorrect grammar #5822

5.0.0 - 2026-01-23

no changes

5.0.0.rc - 2025-12-31

  • breaking changes
    • Drop support to Ruby < 2.7

    • Drop support to Rails < 7.0

    • Remove deprecated :bypass option from sign_in helper, use bypass_sign_in instead. #5803

    • Remove deprecated devise_error_messages! helper, use render "devise/shared/error_messages", resource: resource instead. #5803

    • Remove deprecated scope second argument from sign_in(resource, :admin) controller test helper, use sign_in(resource, scope: :admin) instead. #5803

    • Remove deprecated Devise::TestHelpers, use Devise::Test::ControllerHelpers instead. #5803

    • Remove deprecated Devise::Models::Authenticatable::BLACKLIST_FOR_SERIALIZATION #5598

    • Remove deprecated Devise.activerecord51? method.

    • Remove SecretKeyFinder and use app.secret_key_base as the default secret key for Devise.secret_key if a custom Devise.secret_key is not provided.

      This is potentially a breaking change because Devise previously used the following order to find a secret key:

      app.credentials.secret_key_base > app.secrets.secret_key_base > application.config.secret_key_base > application.secret_key_base
      

      Now, it always uses application.secret_key_base. Make sure you're using the same secret key after the upgrade; otherwise, previously generated tokens for recoverable, lockable, and confirmable will be invalid. #5645

    • Change password instructions button label on devise view from Send me reset password instructions to Send me password reset instructions #5515

    • Change <br> tags separating form elements to wrapping them in <p> tags #5494

    • Replace [data-turbo-cache=false] with [data-turbo-temporary] on devise/shared/error_messages partial. This has been deprecated by Turbo since v7.3.0 (released on Mar 1, 2023).

... (truncated)

Commits
  • 9ea459d Release v5.0.4 with sec fix for timeoutable
  • 025fe21 Merge commit from fork
  • 7ca7ed9 Add GHSA link to the v5.0.3 sec fix changelog entry [ci skip]
  • 605de86 Update links to https [ci skip]
  • 5e3a8bf Bundle update
  • 5d20277 Cleanup old Rails.version check for db migration path
  • 4ffb0b7 Fix Gemfile for Rails 7.2, incorrectly testing against 7.1
  • 2f80920 Release v5.0.3
  • 5334707 Add CVE to changelog [ci skip]
  • 0252777 Fix race condition vulnerability, by ensuring the unconfirmed_email is alwa...
  • Additional commits viewable in compare view

Updates devise_token_auth from 1.2.6 to 1.3.0

Commits

Updates good_job from 4.19.2 to 4.19.3

Release notes

Sourced from good_job's releases.

v4.19.3

Review the Changelog for more details.

What's Changed

New Contributors

Full Changelog: bensheldon/good_job@v4.19.2...v4.19.3

Changelog

Sourced from good_job's changelog.

v4.19.3 (2026-09-21)

Full Changelog

Implemented enhancements:

Fixed bugs:

  • Use GoodJob::Job.table_name instead of hardcoded good_jobs #1815 (gap777)

Closed issues:

  • Hardcoded table names interfere with applications using custom table names. #1814

Merged pull requests:

Commits
  • c83ab77 Release good_job v4.19.3
  • f67869e Add Azerbaijani locale (#1813)
  • 3bb7679 Fix alphabetization of demo schema.rb columns (#1818)
  • b457a0b Bump github/codeql-action from 4.37.3 to 4.37.9 (#1809)
  • 82822c8 Use GoodJob::Job.table_name instead of hardcoded good_jobs (#1815)
  • 628123f Pin json < 3 as a temporary workaround (#1817)
  • 2d8ebb1 Deprecate the fallback when probe_handler can't be used (#1808)
  • 5fcde48 Add time range controls to dashboard time-series charts (#1782)
  • 33c805e Add GoodJob::Configuration#valid? to validate Cron configuration (#1796)
  • 1dc18f7 Allow Continuation jobs to be paused (#1778)
  • Additional commits viewable in compare view

Updates newrelic_rpm from 10.6.0 to 10.8.0

Changelog

Sourced from newrelic_rpm's changelog.

v10.8.0

  • Feature: Report a unique hostname for Google Cloud Run Worker Pools and Jobs

    The Cloud Run hostname support added in PR#3609 detected Cloud Run by looking for K_REVISION, which Cloud Run Services set. The agent now also recognizes CLOUD_RUN_REVISION (Worker Pools) and CLOUD_RUN_EXECUTION (Jobs), so utilization.gcp_cloud_run.use_instance_as_host applies to all three resource types. When utilization.gcp_cloud_run.include_revision_in_host is true, the hostname uses whichever of those variables is set, for example {CLOUD_RUN_EXECUTION}-{instance id} on a Job. Issue#3651 Thanks to @​choznerol for contributing this enhancement! PR#3652

  • Feature: Add browser_monitoring.version configuration option

    Customers can now pin the exact browser agent loader version New Relic injects by setting the new browser_monitoring.version configuration option. See the browser agent EOL policy for which versions are currently available and supported.

  • Feature: Add span.kind to background job libraries

    Now, the span.kind attribute will be added to produce and consume operations from background job libraries. This includes ActiveJob, Sidekiq, Resque and DelayedJob. PR#3636

  • Bugfix: DelayedJob instrumentation no longer reinstalls itself on every worker under prepend mode

    When DelayedJob instrumentation is installed via prepend (the default), creating more than one Delayed::Worker in the same process caused the agent to log "Installing DelayedJob instrumentation" and reinitialize the plugin again for each additional worker. This was harmless but noisy; it's now only done once per process, matching the existing chain-instrumentation behavior. PR#3654

  • Bugfix: Allowlisted configuration values are no longer case sensitive

    Configuration options that validate against an allowlist now match values regardless of case. For example, setting slow_sql.record_sql to OBFUSCATED or ObFuScAtEd is now treated the same as obfuscated. Previously, a value with unexpected casing that wasn't an exact match would silently fall back to the default. PR#3645

  • Bugfix: Puma instrumentation works when Puma is lazy-loaded

    With gem "puma", require: false, Puma was not yet loaded when the agent's dependency check ran, so Puma instrumentation would fail to install. The agent now recognizes Puma::RackHandler as evidence that Puma is present, fixing this issue. Thank you @​jdelStrother for finding this issue and providing a solution! PR#3650

v10.7.1

  • Bugfix: Resolve ArgumentError on multi-key operations with Dalli 5.1.0

    This fix updates Dalli instrumentation to accept and forward optional request options arguments in multi and pipelined operations. Our thanks go to @​dbackeus for contributing a fix! PR#3642

  • Bugfix: Async::HTTP requests no longer raise NoMethodError when a segment fails to start

    If the agent encountered an internal error while creating the segment for an Async::HTTP request, the instrumentation went on to use that missing segment and could raise a NoMethodError. This is now fixed, thanks to @​ydah. PR#3640

v10.7.0

  • Feature: Add transaction_tracer.cap_segment_artifacts configuration option

    Long-running transactions with many segments can cause continuously increasing memory usage for the lifetime of the transaction. The agent now offers an opt-in transaction_tracer.cap_segment_artifacts configuration option (defaults to false). When enabled, once transaction_tracer.limit_segments is reached, the agent also stops recording exclusive time for any segments created afterward in that transaction, reducing memory usage at the cost of less accurate timing data for the transaction.PR#3615

  • Feature: Add Puma server-statistics instrumentation

    The agent now samples Puma's cluster-wide server statistics and reports them as Ruby/Puma/* timeslice metrics, including backlog, running, pool_capacity, max_threads, and requests_count. Statistics are sampled in single mode and in clustered mode when preload_app! is enabled. This instrumentation is disabled by default; enable it by setting disable_puma_instrumentation to false. When enabled, the agent starts a reporting thread in the Puma master process to deliver these metrics, which runs an additional agent connection alongside the Puma workers. The sampling interval is configurable via the new puma.sample_rate setting (default 60 seconds). Requires Puma 6.6 or later. See our docs for more information.

    Thanks so much to @​ashleyboehs contributing this new feature. PR#3578

  • Feature: Report a unique hostname for Google Cloud Run instances

... (truncated)

Commits
  • 338082d Merge pull request #3672 from newrelic/prerelease_updates_10.8.0-pre
  • 9702f8d bump version
  • d33c91a Merge pull request #3666 from newrelic/error_inbox_metadata
  • afec839 Merge pull request #3671 from newrelic/update_config_schema
  • 0c08665 use github token for commit instead
  • a54d578 Update lib/tasks/helpers/config.html.erb
  • 5f3757a Update lib/tasks/helpers/config.html.erb
  • aee83f8 Update lib/tasks/helpers/config.html.erb
  • c806f53 Merge pull request #3670 from newrelic/gcp_changelog_comment
  • afced44 update comment and changelog
  • Additional commits viewable in compare view

Updates pagy from 43.6.1 to 43.6.2

Release notes

Sourced from pagy's releases.

Version 43.6.2

Changes in 43.6.2

  • Fix nil records returned for Array collections on page overflow (#920) (Fix #919)

CHANGELOG

Version 43

We needed a leap version to unequivocally signal that it's not just a major version: it's a complete redesign of the legacy code at all levels, usage and API included.

Why 43? Because it's exactly one step beyond "The answer to the ultimate question of life, the Universe, and everything." 😉

Improvements

This version introduces several enhancements, such as new :countish and :keynav_js paginators and improved automation and configuration processes, reducing setup requirements by 99%. The update also includes a simpler API and new interactive development tools, making it a comprehensive upgrade from previous versions.

  • New :countish Paginator
    • Faster than OFFSET and supporting the full UI
  • New Keynav Pagination
    • The pagy-exclusive technique using the fastest keyset pagination alongside all frontend helpers.
  • New interactive dev-tools
    • New PagyWand to integrate the pagy CSS with your app themes.
    • New Pagy AI available right inside your own app.
  • Intelligent automation
  • Simpler API
    • You solely need the pagy method and the @​pagy instance to paginate any collection and use any navigation tag and helper.
    • Methods are autoloaded only if used, and consume no memory otherwise.
    • Methods have narrower scopes and can be overridden without deep knowledge.
  • New documentation
    • Very concise, straightforward, and easy to navigate and understand.

Upgrade to 43

See the Upgrade Guide

Changelog

Sourced from pagy's changelog.

Version 43.6.2

  • Fix nil records returned for Array collections on page overflow (#920) (Fix #919)
Commits
  • e854305 Merge branch 'dev'
  • 6f0ebbe Version 43.6.2
  • 871fb4a 💎 Fix nil records returned for Array collections on page overflow (#920) (Fix...
  • 1ad8485 Fix broken links in CHANGELOG.md when displayed on GitHub (close #913)
  • 5248145 Update gems and packages
  • 4b5f6f9 Update RM run configs
  • 44afd3f Improve docs templating
  • 2d72e39 Improve Retype config, allowing url override to github actions (#918)
  • See full diff in compare view

Updates annotaterb from 4.24.0 to 4.25.0

Changelog

Sourced from annotaterb's changelog.

v4.25.0 (2026-09-17)

Full Changelog

Fixed bugs:

  • Missing unique indexes in annotations #390
  • Related files are matched globally by unqualified model name, so models with the same basename in different packs overwrite each other's annotations (breaks --frozen) #367
  • When format_markdown: true, annotations get written duplicated into models that already have annotations. #355

Closed issues:

  • Foreign-key annotation crashes with ArgumentError when unnamed FKs mix with a composite FK #377
Commits
  • 60e9f7a Release v4.25.0 (#395)
  • 4c94d80 Show index operator classes in annotations (#382)
  • e7a903f Remove unused routes option (#393)
  • db3cd09 Prevent related-file collisions between models with the same basename (#374)
  • a0283f6 Fix enum-backed integer columns annotations (#380)
  • d270071 Bump github/codeql-action from 4.37.9 to 4.38.0 (#394)
  • 7d8dc60 Update annotated model in README (#385)
  • 80d54f5 Use native prefix predicate in YAML parser (#387)
  • 3f971bb Fix multi-database annotation removal fixture targeting (#386)
  • ae89369 Fix ArgumentError sorting unnamed foreign keys when one is composite (#378)
  • Additional commits viewable in compare view

Updates brakeman from 8.0.5 to 8.0.6

Release notes

Sourced from brakeman's releases.

8.0.6 - EOL Dates

Changelog

Sourced from brakeman's changelog.

8.0.6 - 2026-08-13

  • Fix EOL date for Rails 8.0 (yeaseul-kim)
  • Add EOL dates for Rails 8.1 and Ruby 4.0
  • Fix command injection false positives (Jacob Evelyn)
  • Fix unused variable warning (viralpraxis)
Commits
  • fffc483 Bump to 8.0.6
  • b7218fe Update CHANGES
  • c6be6cc Merge pull request #2034 from yeaseul-kim/fix-rails-8-0-eol-date
  • 4c191dd Fix EOL date for Rails 8.0
  • e7bda16 Merge pull request #2033 from presidentbeef/add-ruby-rails-eol-dates
  • dd4f0b9 Add EOL date for Ruby 4.0
  • 7ca100a Add EOL date for Rails 8.1
  • a53a456 Merge pull request #2022 from JacobEvelyn/main
  • bf3fdc9 Merge pull request #2030 from viralpraxis/fix-unusued-gem-release-date
  • 20f74ac Brakeman.ensure_latest: fix unsued release_date variable
  • Additional commits viewable in compare view

Updates rubocop from 1.88.2 to 1.91.0

Release notes

Sourced from rubocop's releases.

RuboCop v1.91.0

New features

  • #15631: Add a preview channel for unstable behavior. ([@​bbatsov][])
  • #15627: Add a SARIF formatter. ([@​bbatsov][])
  • #15686: Add AllCops: FailLevel, the configuration equivalent of --fail-level. ([@​bbatsov][])
  • #15650: Add AllowedDirectives option to Style/DisableCopsWithinSourceCodeDirective, exempting directive kinds such as generated rubocop:todo comments. ([@​bbatsov][])
  • #15629: Add --changed to inspect only the files git says changed. ([@​bbatsov][])
  • #15628: Add --diff to preview autocorrection without writing files. ([@​bbatsov][])
  • #15615: Add new Lint/MisplacedMagicComment cop to flag magic comments in positions where Ruby ignores them. ([@​bbatsov][])
  • #15600: Add the rubocop:enable-next directive to re-enable cops for the next statement only. ([@​bbatsov][])
  • #15600: Add the rubocop:next directive, combining push-style +/- arguments with disable-next's statement scope. ([@​bbatsov][])
  • #15363: Let a cop's entry in the default configuration carry a Preview section with the defaults it is expected to adopt in the next major release, applied under Preview. ([@​bbatsov][])

Bug fixes

  • #15349: Fix a false positive for Style/RedundantRegexpCharacterClass with \8/\9. ([@​bbatsov][])
  • #15646: Fix an error for Layout/ElseAlignment when else is used with rescue in a class, module, or singleton class body. ([@​viralpraxis][])
  • #15613: Fix an error for Layout/HashAlignment when a hash value starts on the line below its key. ([@​viralpraxis][])
  • #15623: Fix an error for Layout/HashAlignment when the first pair of a hash omits its value, and an incorrect autocorrection when a later pair does. ([@​viralpraxis][])
  • #15602: Fix an error for Layout/IndentationWidth on under-indented code with tab indentation. ([@​Starlexxx][])
  • #15672: Fix an error for Lint/RedundantCopDisableDirective when a file contains more than one rubocop:push/rubocop:pop pair. ([@​koic][])
  • #15625: Fix an error for Style/AccessModifierDeclarations when a body repeats the same access modifier. ([@​viralpraxis][])
  • #15603: Fix an error for Style/AccessModifierDeclarations with EnforcedStyle: inline when an access modifier is the body of an if without an else branch. ([@​viralpraxis][])
  • #15604: Fix an error for Style/ConstantVisibility when a visibility declaration splats anything other than an array literal, e.g. private_constant(*constants(false)). ([@​viralpraxis][])
  • #15647: Fix an error for Style/DocumentationMethod when an inline module_function/ruby2_keywords def is preceded by another argument. ([@​viralpraxis][])
  • #15680: Fix an error for Style/EndlessMethod when a method definition is nested inside another method definition. ([@​viralpraxis][])
  • #15674: Fix an error for Style/FloatDivision when using EnforcedStyle: fdiv and one operand of a float division is itself a parenthesized float division. ([@​viralpraxis][])
  • #15624: Fix an error for Style/HashLookupMethod when the looked-up key is itself a hash lookup. ([@​viralpraxis][])
  • #15642: Fix an error for Style/HashSyntax when hash rockets are enforced and a hash value repeats its key. ([@​viralpraxis][])
  • #15634: Fix an incorrect autocorrect for Lint/LiteralAsCondition when the other operand is a parenthesized return. ([@​Starlexxx][])
  • #15648: Fix an incorrect autocorrect for Lint/ParenthesesAsGroupedExpression when the parentheses contain and, or, not, or a modifier expression. ([@​Starlexxx][])
  • #15612: Fix an incorrect autocorrect for Naming/BlockForwarding with Style/MethodDefParentheses. ([@​Starlexxx][])
  • #15680: Fix an incorrect autocorrect for Style/EndlessMethod when using EnforcedStyle: require_always and the method body has a rescue or ensure clause. ([@​viralpraxis][])
  • #15669: Fix an incorrect autocorrect for Style/FloatDivision when using EnforcedStyle: fdiv and the divisor is a method call with parenthesized arguments. ([@​viralpraxis][])
  • #15678: Fix an incorrect autocorrect for Style/For when using EnforcedStyle: for and the block body has a rescue or ensure clause. ([@​viralpraxis][])
  • #15645: Fix an incorrect autocorrect for Style/GuardClause with Style/MissingElse. ([@​Starlexxx][])
  • #15668: Fix an incorrect autocorrect for Style/MethodCallWithArgsParentheses when EnforcedStyle: omit_parentheses is used together with Style/TrailingCommaInArguments. ([@​viralpraxis][])
  • #15347: Fix an incorrect autocorrect for Style/NestedModifier. ([@​bbatsov][])
  • #15347: Fix an incorrect autocorrect for Style/NonNilCheck. ([@​bbatsov][])
  • #15347: Fix an incorrect autocorrect for Style/Not with a flip-flop or assignment. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantDoubleSplatHashBraces with a braced merge argument. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantParentheses around and/or. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantRegexpConstructor with %r{} delimiters. ([@​bbatsov][])
  • #15614: Fix an infinite loop between Layout/ArgumentAlignment and Layout/HashAlignment with separator style. ([@​Starlexxx][])
  • #15599: Fix an infinite loop error for Layout/CommentIndentation when many comment blocks with the same indentation are separated by empty lines. ([@​Starlexxx][])
  • #15597: Fix an infinite loop error for Layout/EmptyLinesAfterModuleInclusion when a module inclusion is directly before rescue. ([@​Starlexxx][])
  • #15617: Fix an infinite loop between Layout/ExtraSpacing with ForceEqualSignAlignment and Layout/SpaceAroundOperators. ([@​Starlexxx][])
  • #15638: Fix an infinite loop error for Layout/FirstArrayElementIndentation with Layout/ArrayAlignment when EnforcedStyle: with_fixed_indentation is configured. ([@​RedZapdos123][])
  • #15639: Fix an infinite loop error for Layout/FirstParameterIndentation with Layout/ParameterAlignment when EnforcedStyle: with_fixed_indentation is configured. ([@​RedZapdos123][])

... (truncated)

Changelog

Sourced from rubocop's changelog.

1.91.0 (2026-09-10)

New features

  • #15631: Add a preview channel for unstable behavior. ([@​bbatsov][])
  • #15627: Add a SARIF formatter. ([@​bbatsov][])
  • #15686: Add AllCops: FailLevel, the configuration equivalent of --fail-level. ([@​bbatsov][])
  • #15650: Add AllowedDirectives option to Style/DisableCopsWithinSourceCodeDirective, exempting directive kinds such as generated rubocop:todo comments. ([@​bbatsov][])
  • #15629: Add --changed to inspect only the files git says changed. ([@​bbatsov][])
  • #15628: Add --diff to preview autocorrection without writing files. ([@​bbatsov][])
  • #15615: Add new Lint/MisplacedMagicComment cop to flag magic comments in positions where Ruby ignores them. ([@​bbatsov][])

Bumps the bundler group with 17 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [aws-sdk-s3](https://github.com/aws/aws-sdk-ruby) | `1.228.1` | `1.232.1` |
| [bootsnap](https://github.com/rails/bootsnap) | `1.24.6` | `1.26.0` |
| [devise](https://github.com/heartcombo/devise) | `4.9.4` | `5.0.4` |
| [devise_token_auth](https://github.com/lynndylanhurley/devise_token_auth) | `1.2.6` | `1.3.0` |
| [good_job](https://github.com/bensheldon/good_job) | `4.19.2` | `4.19.3` |
| [newrelic_rpm](https://github.com/newrelic/newrelic-ruby-agent) | `10.6.0` | `10.8.0` |
| [pagy](https://github.com/ddnexus/pagy) | `43.6.1` | `43.6.2` |
| [annotaterb](https://github.com/drwl/annotaterb) | `4.24.0` | `4.25.0` |
| [brakeman](https://github.com/presidentbeef/brakeman) | `8.0.5` | `8.0.6` |
| [rubocop](https://github.com/rubocop/rubocop) | `1.88.2` | `1.91.0` |
| [rubocop-performance](https://github.com/rubocop/rubocop-performance) | `1.26.1` | `1.27.0` |
| [rubocop-rails](https://github.com/rubocop/rubocop-rails) | `2.36.0` | `2.38.0` |
| [parallel_tests](https://github.com/grosser/parallel_tests) | `5.7.0` | `5.8.0` |
| [pg_query](https://github.com/pganalyze/pg_query) | `6.2.2` | `6.2.3` |
| [rspec-openapi](https://github.com/exoego/rspec-openapi) | `0.31.0` | `0.34.0` |
| [selenium-webdriver](https://github.com/SeleniumHQ/selenium) | `4.46.0` | `4.49.0` |
| [webmock](https://github.com/bblimke/webmock) | `3.26.2` | `3.26.4` |



Updates `aws-sdk-s3` from 1.228.1 to 1.232.1
- [Release notes](https://github.com/aws/aws-sdk-ruby/releases)
- [Changelog](https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sdk-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-ruby/commits)

Updates `bootsnap` from 1.24.6 to 1.26.0
- [Release notes](https://github.com/rails/bootsnap/releases)
- [Changelog](https://github.com/rails/bootsnap/blob/main/CHANGELOG.md)
- [Commits](rails/bootsnap@v1.24.6...v1.26.0)

Updates `devise` from 4.9.4 to 5.0.4
- [Release notes](https://github.com/heartcombo/devise/releases)
- [Changelog](https://github.com/heartcombo/devise/blob/main/CHANGELOG.md)
- [Commits](heartcombo/devise@v4.9.4...v5.0.4)

Updates `devise_token_auth` from 1.2.6 to 1.3.0
- [Changelog](https://github.com/lynndylanhurley/devise_token_auth/blob/master/CHANGELOG.md)
- [Commits](lynndylanhurley/devise_token_auth@v1.2.6...v1.3.0)

Updates `good_job` from 4.19.2 to 4.19.3
- [Release notes](https://github.com/bensheldon/good_job/releases)
- [Changelog](https://github.com/bensheldon/good_job/blob/main/CHANGELOG.md)
- [Commits](bensheldon/good_job@v4.19.2...v4.19.3)

Updates `newrelic_rpm` from 10.6.0 to 10.8.0
- [Release notes](https://github.com/newrelic/newrelic-ruby-agent/releases)
- [Changelog](https://github.com/newrelic/newrelic-ruby-agent/blob/dev/CHANGELOG.md)
- [Commits](newrelic/newrelic-ruby-agent@10.6.0...10.8.0)

Updates `pagy` from 43.6.1 to 43.6.2
- [Release notes](https://github.com/ddnexus/pagy/releases)
- [Changelog](https://github.com/ddnexus/pagy/blob/master/docs/CHANGELOG.md)
- [Commits](ddnexus/pagy@43.6.1...43.6.2)

Updates `annotaterb` from 4.24.0 to 4.25.0
- [Changelog](https://github.com/drwl/annotaterb/blob/main/CHANGELOG.md)
- [Commits](drwl/annotaterb@v4.24.0...v4.25.0)

Updates `brakeman` from 8.0.5 to 8.0.6
- [Release notes](https://github.com/presidentbeef/brakeman/releases)
- [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md)
- [Commits](presidentbeef/brakeman@v8.0.5...v8.0.6)

Updates `rubocop` from 1.88.2 to 1.91.0
- [Release notes](https://github.com/rubocop/rubocop/releases)
- [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.md)
- [Commits](rubocop/rubocop@v1.88.2...v1.91.0)

Updates `rubocop-performance` from 1.26.1 to 1.27.0
- [Release notes](https://github.com/rubocop/rubocop-performance/releases)
- [Changelog](https://github.com/rubocop/rubocop-performance/blob/master/CHANGELOG.md)
- [Commits](rubocop/rubocop-performance@v1.26.1...v1.27.0)

Updates `rubocop-rails` from 2.36.0 to 2.38.0
- [Release notes](https://github.com/rubocop/rubocop-rails/releases)
- [Changelog](https://github.com/rubocop/rubocop-rails/blob/master/CHANGELOG.md)
- [Commits](rubocop/rubocop-rails@v2.36.0...v2.38.0)

Updates `parallel_tests` from 5.7.0 to 5.8.0
- [Changelog](https://github.com/grosser/parallel_tests/blob/master/CHANGELOG.md)
- [Commits](grosser/parallel_tests@v5.7.0...v5.8.0)

Updates `pg_query` from 6.2.2 to 6.2.3
- [Changelog](https://github.com/pganalyze/pg_query/blob/main/CHANGELOG.md)
- [Commits](pganalyze/pg_query@v6.2.2...v6.2.3)

Updates `rspec-openapi` from 0.31.0 to 0.34.0
- [Release notes](https://github.com/exoego/rspec-openapi/releases)
- [Changelog](https://github.com/exoego/rspec-openapi/blob/master/CHANGELOG.md)
- [Commits](exoego/rspec-openapi@v0.31.0...v0.34.0)

Updates `selenium-webdriver` from 4.46.0 to 4.49.0
- [Release notes](https://github.com/SeleniumHQ/selenium/releases)
- [Changelog](https://github.com/SeleniumHQ/selenium/blob/trunk/rb/CHANGES)
- [Commits](SeleniumHQ/selenium@selenium-4.46.0...selenium-4.49.0)

Updates `webmock` from 3.26.2 to 3.26.4
- [Release notes](https://github.com/bblimke/webmock/releases)
- [Changelog](https://github.com/bblimke/webmock/blob/master/CHANGELOG.md)
- [Commits](bblimke/webmock@v3.26.2...v3.26.4)

---
updated-dependencies:
- dependency-name: aws-sdk-s3
  dependency-version: 1.232.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: bootsnap
  dependency-version: 1.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: devise
  dependency-version: 5.0.4
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: bundler
- dependency-name: devise_token_auth
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: good_job
  dependency-version: 4.19.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bundler
- dependency-name: newrelic_rpm
  dependency-version: 10.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: pagy
  dependency-version: 43.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bundler
- dependency-name: annotaterb
  dependency-version: 4.25.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: brakeman
  dependency-version: 8.0.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bundler
- dependency-name: rubocop
  dependency-version: 1.91.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: rubocop-performance
  dependency-version: 1.27.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: rubocop-rails
  dependency-version: 2.38.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: parallel_tests
  dependency-version: 5.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: pg_query
  dependency-version: 6.2.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bundler
- dependency-name: rspec-openapi
  dependency-version: 0.34.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: selenium-webdriver
  dependency-version: 4.49.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: webmock
  dependency-version: 3.26.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bundler
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Sep 25, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 2, 2026
@dependabot
dependabot Bot deleted the dependabot/bundler/bundler-5ac79145f6 branch October 2, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants