build(deps): bump the bundler group with 9 updates - #1064
Merged
Conversation
Bumps the bundler group with 9 updates: | Package | From | To | | --- | --- | --- | | [sorbet-runtime](https://github.com/sorbet/sorbet) | `0.6.13433` | `0.6.13454` | | [rubocop](https://github.com/rubocop/rubocop) | `1.89.0` | `1.90.0` | | [rubocop-sorbet](https://github.com/shopify/rubocop-sorbet) | `0.14.0` | `0.15.0` | | [sorbet](https://github.com/sorbet/sorbet) | `0.6.13433` | `0.6.13454` | | [sorbet-static-and-runtime](https://github.com/sorbet/sorbet) | `0.6.13433` | `0.6.13454` | | [net-protocol](https://github.com/ruby/net-protocol) | `0.2.2` | `0.3.0` | | [rbs](https://github.com/ruby/rbs) | `4.1.3` | `4.2.0` | | [require-hooks](https://github.com/ruby-next/require-hooks) | `0.4.1` | `0.5.1` | | [sorbet-static](https://github.com/sorbet/sorbet) | `0.6.13433` | `0.6.13454` | Updates `sorbet-runtime` from 0.6.13433 to 0.6.13454 - [Release notes](https://github.com/sorbet/sorbet/releases) - [Commits](https://github.com/sorbet/sorbet/commits) Updates `rubocop` from 1.89.0 to 1.90.0 - [Release notes](https://github.com/rubocop/rubocop/releases) - [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.md) - [Commits](rubocop/rubocop@v1.89.0...v1.90.0) Updates `rubocop-sorbet` from 0.14.0 to 0.15.0 - [Release notes](https://github.com/shopify/rubocop-sorbet/releases) - [Commits](Shopify/rubocop-sorbet@v0.14.0...v0.15.0) Updates `sorbet` from 0.6.13433 to 0.6.13454 - [Release notes](https://github.com/sorbet/sorbet/releases) - [Commits](https://github.com/sorbet/sorbet/commits) Updates `sorbet-static-and-runtime` from 0.6.13433 to 0.6.13454 - [Release notes](https://github.com/sorbet/sorbet/releases) - [Commits](https://github.com/sorbet/sorbet/commits) Updates `net-protocol` from 0.2.2 to 0.3.0 - [Release notes](https://github.com/ruby/net-protocol/releases) - [Commits](ruby/net-protocol@v0.2.2...v0.3.0) Updates `rbs` from 4.1.3 to 4.2.0 - [Release notes](https://github.com/ruby/rbs/releases) - [Changelog](https://github.com/ruby/rbs/blob/master/CHANGELOG.md) - [Commits](ruby/rbs@v4.1.3...v4.2.0) Updates `require-hooks` from 0.4.1 to 0.5.1 - [Changelog](https://github.com/ruby-next/require-hooks/blob/master/CHANGELOG.md) - [Commits](ruby-next/require-hooks@v0.4.1...v0.5.1) Updates `sorbet-static` from 0.6.13433 to 0.6.13454 - [Release notes](https://github.com/sorbet/sorbet/releases) - [Commits](https://github.com/sorbet/sorbet/commits) --- updated-dependencies: - dependency-name: sorbet-runtime dependency-version: 0.6.13454 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: bundler - dependency-name: rubocop dependency-version: 1.90.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: bundler - dependency-name: rubocop-sorbet dependency-version: 0.15.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: bundler - dependency-name: sorbet dependency-version: 0.6.13454 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: bundler - dependency-name: sorbet-static-and-runtime dependency-version: 0.6.13454 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: bundler - dependency-name: net-protocol dependency-version: 0.3.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: bundler - dependency-name: rbs dependency-version: 4.2.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: bundler - dependency-name: require-hooks dependency-version: 0.5.1 dependency-type: indirect update-type: version-update:semver-minor dependency-group: bundler - dependency-name: sorbet-static dependency-version: 0.6.13454 dependency-type: indirect update-type: version-update:semver-patch dependency-group: bundler ... Signed-off-by: dependabot[bot] <support@github.com>
- `Rails/OutputSafety`: build markup with `safe_join` so every interpolated fragment is escaped rather than trusted - `Style/StringHashKeys`: OmniAuth test mode already injects `omniauth.auth`, so the string-keyed `env` hash was unused, and `OmniAuth::AuthHash` stringifies symbol keys itself - `RSpec/MultipleExpectations`: `include` takes several values - enable `Style/DisableCopsWithinSourceCodeDirective` to keep it that way, which also fixes the new RuboCop 1.90 `Style/DirectiveScope` failure
MikeMcQuaid
force-pushed
the
dependabot/bundler/bundler-bdc314317b
branch
from
September 4, 2026 12:23
8de760f to
967e5ec
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the bundler group with 9 updates:
0.6.134330.6.134541.89.01.90.00.14.00.15.00.6.134330.6.134540.6.134330.6.134540.2.20.3.04.1.34.2.00.4.10.5.10.6.134330.6.13454Updates
sorbet-runtimefrom 0.6.13433 to 0.6.13454Release notes
Sourced from sorbet-runtime's releases.
... (truncated)
Commits
Updates
rubocopfrom 1.89.0 to 1.90.0Release notes
Sourced from rubocop's releases.
... (truncated)
Changelog
Sourced from rubocop's changelog.
... (truncated)
Commits
f1b25e1Cut 1.9072895f6Update Changelog7042de6Move op_method? before the shadowing helpers4b14dd2Fix an incorrect autocorrect forNaming/BinaryOperatorParameterName5d221ac[Fix #10046] FixLint/UselessMethodDefinitionfalse positive for methods wi...5070fc3[Fix #15111] AddNumberOfEmptyLinesoption to `Layout/EmptyLineAfterMagicCo...496eb65[Fix #9543] Preserve escape notation inStyle/StringConcatenationautocorrect75b3622Remove a directive's--reason along with the directive858d8a8Merge pull request #15596 from koic/add_real_last_column_to_offense15557b0AddOffense#real_last_columnand use it inJSONFormatterUpdates
rubocop-sorbetfrom 0.14.0 to 0.15.0Release notes
Sourced from rubocop-sorbet's releases.
Commits
a88afd4Release v0.15.0c3e4550Merge pull request #405 from Shopify/t-must-rbs-autocorrection946e63bAdd trailing comment autocorrection test673b342Merge pull request #409 from Shopify/t-absurd-inline-else0dac722Test inline unless absurd autocorrection6979d2eHandle inline if else T.absurd autocorrection0ce61e7Autocorrect inline else T.absurd calls6468538Merge pull request #404 from Shopify/t-unsafe-rbs-autocorrection5a5dc70Merge pull request #407 from Shopify/t-let-rbs-autocorrection9cf7734Merge pull request #406 from Shopify/t-cast-rbs-autocorrectionUpdates
sorbetfrom 0.6.13433 to 0.6.13454Release notes
Sourced from sorbet's releases.
... (truncated)
Commits
Updates
sorbet-static-and-runtimefrom 0.6.13433 to 0.6.13454Release notes
Sourced from sorbet-static-and-runtime's releases.
... (truncated)
Commits
Updates
net-protocolfrom 0.2.2 to 0.3.0Release notes
Sourced from net-protocol's releases.
Commits
fb347d5v0.3.074c2348Merge pull request #67 from ruby/readuntil-limit6ffd258Trim the comments added with the readuntil rewinde1b38d9Add limit option to Net::BufferedIO#readuntil716719eMerge pull request #66 from ruby/readuntil-chunk-boundary0dbbaeaIgnore Gemfile.lock215cc35Add regression tests for the readuntil rewind84ef3abFix readuntil missing a terminator that spans two readsc1d4563Merge pull request #65 from ruby/dependabot/github_actions/rubygems/release-g...0c9e23bBump rubygems/release-gem from 1.4.0 to 1.4.1Updates
rbsfrom 4.1.3 to 4.2.0Release notes
Sourced from rbs's releases.
... (truncated)
Changelog
Sourced from rbs's changelog.
Commits
8aee3b6Merge pull request #3096 from ruby/claude/4-2-release-tasks-h6thzx6f97c87Version 4.2.003d4281Merge pull request #2966 from zonuexe/fix/concrete-untyped-returnsbdecacfMake putc signatures type-preserving overloads69539d6Replace deterministicuntypedreturn types with concrete typesc9957e4Merge pull request #3037 from infiton/rxc/declare-singleton-instance-methods1f40487Merge pull request #3095 from ruby/claude/4-2-release-tasks-h6thzxe721ad1Drop runtime support for Ruby 3.2584b4cfMerge pull request #3092 from ruby/claude/rbs-ci-failure-sinnfde709673Merge pull request #3090 from ruby/claude/release-4-2-0-pre-1-vyzb7gUpdates
require-hooksfrom 0.4.1 to 0.5.1Changelog
Sourced from require-hooks's changelog.
Commits
602f718Bump 0.5.1493070b+ bootsnap: external Bootsnap cache inputs (#6)d82daa8Bump 0.5.0483e617Use Bootsnap compiler namespaces for hook caches (#5)9238cdaFix Bootsnap version hash overrideUpdates
sorbet-staticfrom 0.6.13433 to 0.6.13454Release notes
Sourced from sorbet-static's releases.
... (truncated)
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions