Skip to content

Bump the bundler-minor-patch group with 4 updates - #74

Merged
VSN2015 merged 1 commit into
masterfrom
dependabot/bundler/bundler-minor-patch-726e0fca9f
Sep 29, 2026
Merged

VSN2015 merged 1 commit into
masterfrom
dependabot/bundler/bundler-minor-patch-726e0fca9f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the bundler-minor-patch group with 4 updates: actionpack, activerecord, railties and activesupport.

Updates actionpack from 8.1.3.1 to 8.1.4

Release notes

Sourced from actionpack's releases.

8.1.4

Active Support

  • Fix the debug error page rendering for SyntaxErrors with multi-line messages.

    Marco Roth

  • Make ActiveSupport::JSON.decode compatible with the upcoming json 3.0 gem.

    Earlopain

  • Fix number_to_human_size crashing for sizes above a terabyte by supporting petabyte, exabyte, and zettabyte storage units.

    Kenta Ishizaki

  • Fix Range#sole raising NoMethodError when the enumerable core extension isn't already loaded.

    Kenta Ishizaki

  • Fix ActiveSupport::Cache::FileStore raising NameError for FileUtils when fileutils isn't already loaded.

    Kenta Ishizaki

  • Fix Enumerable#in_order_of with filter: true dropping nil elements explicitly named in the series.

    Kenta Ishizaki

  • Keep HashWithIndifferentAccess#filter returning a HashWithIndifferentAccess instead of a plain Hash.

    Kenta Ishizaki

  • Fix number_to_human and number_to_human_size crashing when :precision is nil.

    Kenta Ishizaki

  • Fix ActiveSupport::InheritableOptions#to_h to recursively flatten nested InheritableOptions parents.

    Andrew Novoselac

  • Fix ActiveSupport::StructuredEventSubscriber.debug_only leaking debug-only methods across subscriber subclasses.

    Kenta Ishizaki

... (truncated)

Changelog

Sourced from actionpack's changelog.

Rails 8.1.4 (September 24, 2026)

  • Fix the debug error page to not attempt to read source fragments from directory paths.

    Marco Roth

  • Apply source value mappings to dynamic Permissions Policy sources.

    Dynamic Permissions Policy sources (procs) now have source mappings applied to their resolved values, the same as static sources.

    Kenta Ishizaki

  • Allow ActionDispatch::Http::URL.path_for with trailing_slash: true and a blank path to accept query params and an anchor.

    Previously the blank path used a frozen "/", which raised a FrozenError when appending the query string.

    Kenta Ishizaki

  • Avoid mutating the params hash passed to ActionDispatch::Http::URL.url_for.

    Kenta Ishizaki

  • Honor falsy values (e.g. format: false, anchor: false) passed in the deprecated positional-hash form of routing DSL methods.

    Previously, false values were silently dropped without emitting a deprecation warning, causing the deprecated hash form to produce different routes than the keyword form.

    Kenta Ishizaki

  • Honor the deprecated namespace hash :path, :shallow_path, and :shallow_prefix options when passed as false.

    Kenta Ishizaki

  • Fix the deprecated scope hash :except option to apply to except instead of only.

    Kenta Ishizaki

  • Reject malformed hosts with extra ports in ActionDispatch::HostAuthorization.

    When an allowed host is configured with an explicit port, a Host header with an additional port (e.g. www.example.com:80:80) is no longer accepted.

... (truncated)

Commits
  • c3466ea Preparing for 8.1.4 release
  • e6288a8 Update CHANGELOGs for 8-1-stable backports
  • 215952f Merge pull request #58727 from marcoroth/multiline-syntax-errors
  • 6785886 Merge pull request #58688 from byroot/upgrade-rubocop
  • 583773b Only omit blank strings in route generation
  • 40d0879 Merge pull request #58412 from carldaws/optional-segment-blank-omission
  • bf26808 Merge branch '8-1-sec' into 8-1-stable
  • 69e4aa7 Merge pull request #58241 from afurm/af/normalize-mixed-case-percent-escapes
  • fb34e6c Follow up to rails/rails#56393
  • b00bb28 Merge pull request #57939 from 55728/fix-permissions-policy-dynamic-source-ma...
  • Additional commits viewable in compare view

Updates activerecord from 8.1.3.1 to 8.1.4

Release notes

Sourced from activerecord's releases.

8.1.4

Active Support

  • Fix the debug error page rendering for SyntaxErrors with multi-line messages.

    Marco Roth

  • Make ActiveSupport::JSON.decode compatible with the upcoming json 3.0 gem.

    Earlopain

  • Fix number_to_human_size crashing for sizes above a terabyte by supporting petabyte, exabyte, and zettabyte storage units.

    Kenta Ishizaki

  • Fix Range#sole raising NoMethodError when the enumerable core extension isn't already loaded.

    Kenta Ishizaki

  • Fix ActiveSupport::Cache::FileStore raising NameError for FileUtils when fileutils isn't already loaded.

    Kenta Ishizaki

  • Fix Enumerable#in_order_of with filter: true dropping nil elements explicitly named in the series.

    Kenta Ishizaki

  • Keep HashWithIndifferentAccess#filter returning a HashWithIndifferentAccess instead of a plain Hash.

    Kenta Ishizaki

  • Fix number_to_human and number_to_human_size crashing when :precision is nil.

    Kenta Ishizaki

  • Fix ActiveSupport::InheritableOptions#to_h to recursively flatten nested InheritableOptions parents.

    Andrew Novoselac

  • Fix ActiveSupport::StructuredEventSubscriber.debug_only leaking debug-only methods across subscriber subclasses.

    Kenta Ishizaki

... (truncated)

Changelog

Sourced from activerecord's changelog.

Rails 8.1.4 (September 24, 2026)

  • Avoid deadlocks when concurrent find_or_create_by calls read back the same record within MySQL transactions.

    Use a shared lock for the read after a duplicate insert, preserving visibility under REPEATABLE READ without upgrading competing shared locks to exclusive locks. This also applies to create_or_find_by and the bang variants of both methods.

    Fixes #54281.

    Kirsten Westeinde

  • Filter the database password out of failed db: task command error messages.

    Ngan Pham

  • Fix ActiveRecord::TypeCaster::Connection sometimes leaking a checked-out connection.

    Hartley McGuire

  • Fix PostgreSQL exclusion constraints with multiline expressions being parsed incorrectly during schema introspection.

    Jake McAllister

  • Fix async ActiveRecord::StatementCache#execute raising an error for out-of-range bind values instead of returning an empty result.

    viralpraxis

  • Fix where clauses with column-tuple syntax not resolving references to other tables.

    Chris Gunther

  • Fix distinct: true being ignored by average.

    Kenta Ishizaki

  • Fix belongs_to change tracking for composite foreign keys.

    Only the first foreign key column was checked for changes; now all foreign key columns are checked.

    Anas Khan

  • Make add_column(if_not_exists: true) reversible.

... (truncated)

Commits
  • c3466ea Preparing for 8.1.4 release
  • 2670772 Merge pull request #58733 from kwestein/create-or-find-by-deadlock
  • e6288a8 Update CHANGELOGs for 8-1-stable backports
  • 44a7fd4 Merge pull request #58799 from e-akashsaini/fix-tuple-where-key-corrupting-at...
  • 4a230ca Merge pull request #58725 from ngan/np-mysql-cli-trilogy-ssl-keys
  • 062c435 Merge pull request #58726 from ngan/np-redact-password-in-task-errors
  • 36f436f Merge pull request #58714 from joemsak/keepalive-false-config-bug
  • 2a0d899 Merge pull request #58716 from joemsak/checkout-blocking-respects-timeout
  • 6785886 Merge pull request #58688 from byroot/upgrade-rubocop
  • cfa3f46 Fix MessageSerializerTest to handle json 3.x
  • Additional commits viewable in compare view

Updates railties from 8.1.3.1 to 8.1.4

Release notes

Sourced from railties's releases.

8.1.4

Active Support

  • Fix the debug error page rendering for SyntaxErrors with multi-line messages.

    Marco Roth

  • Make ActiveSupport::JSON.decode compatible with the upcoming json 3.0 gem.

    Earlopain

  • Fix number_to_human_size crashing for sizes above a terabyte by supporting petabyte, exabyte, and zettabyte storage units.

    Kenta Ishizaki

  • Fix Range#sole raising NoMethodError when the enumerable core extension isn't already loaded.

    Kenta Ishizaki

  • Fix ActiveSupport::Cache::FileStore raising NameError for FileUtils when fileutils isn't already loaded.

    Kenta Ishizaki

  • Fix Enumerable#in_order_of with filter: true dropping nil elements explicitly named in the series.

    Kenta Ishizaki

  • Keep HashWithIndifferentAccess#filter returning a HashWithIndifferentAccess instead of a plain Hash.

    Kenta Ishizaki

  • Fix number_to_human and number_to_human_size crashing when :precision is nil.

    Kenta Ishizaki

  • Fix ActiveSupport::InheritableOptions#to_h to recursively flatten nested InheritableOptions parents.

    Andrew Novoselac

  • Fix ActiveSupport::StructuredEventSubscriber.debug_only leaking debug-only methods across subscriber subclasses.

    Kenta Ishizaki

... (truncated)

Changelog

Sourced from railties's changelog.

Rails 8.1.4 (September 24, 2026)

  • Include the offending value in the secret_key_base= error message.

    Jean Boussier

  • Load database config when a connection is absent from the shared section.

    database_configuration no longer raises NoMethodError when a shared config section is missing a subsection for a particular connection name.

    Kenta Ishizaki

  • Round-trip the null: false attribute modifier in GeneratedAttribute#to_s.

    rails generate now emits the ! modifier for attributes with null: false, so the generated command string can be used to regenerate the same migration.

    Kenta Ishizaki

  • Fix infinite route reload when after_routes_loaded hooks access routes.

    The :loading state is now held across after_routes_loaded hooks, so a hook that touches routes no longer triggers a redundant reload.

    Chedli Bourguiba

  • Fix LazyRouteSet thrashing when url_helpers are included into Object.

    method_missing and respond_to_missing? now only trigger a route reload for methods ending in _path or _url, preventing every respond_to? call from re-entering the route loader.

    Chedli Bourguiba

  • Add RoutesReloader#loaded to check whether routes have been loaded.

    Rafael Mendonça França

  • Mark routes as loaded when the routes reloader executes standalone.

    RoutesReloader#execute now sets the load state to loaded, so calling it directly (outside of execute_unless_loaded) no longer leaves the reloader in a state where routes are considered unloaded.

    Kenta Ishizaki

  • Make mounted route helpers (e.g. main_app, engine mount proxies) trigger the lazy route load instead of raising NoMethodError when called before routes are drawn.

... (truncated)

Commits
  • c3466ea Preparing for 8.1.4 release
  • e6288a8 Update CHANGELOGs for 8-1-stable backports
  • 6785886 Merge pull request #58688 from byroot/upgrade-rubocop
  • d6cc1f4 Merge pull request #58519 from seuros/fix-lazy-route-set-mounted-helpers
  • fd258d8 Merge pull request #58423 from 55728/fix-routes-reloader-execute-loaded-state
  • f4eb07b Fix RoutesReloaderTest to not get stuck
  • 454f45c Merge pull request #58405 from rails/rmf-loaded-routes-reloader
  • bf26808 Merge branch '8-1-sec' into 8-1-stable
  • 9cc88f6 Merge pull request #58278 from chaadow/fix-lazy-route-set-respond-to-missing-...
  • 6509ef8 Merge pull request #58252 from chaadow/fix-routes-reloader-after-hooks-reload...
  • Additional commits viewable in compare view

Updates activesupport from 8.1.3.1 to 8.1.4

Release notes

Sourced from activesupport's releases.

8.1.4

Active Support

  • Fix the debug error page rendering for SyntaxErrors with multi-line messages.

    Marco Roth

  • Make ActiveSupport::JSON.decode compatible with the upcoming json 3.0 gem.

    Earlopain

  • Fix number_to_human_size crashing for sizes above a terabyte by supporting petabyte, exabyte, and zettabyte storage units.

    Kenta Ishizaki

  • Fix Range#sole raising NoMethodError when the enumerable core extension isn't already loaded.

    Kenta Ishizaki

  • Fix ActiveSupport::Cache::FileStore raising NameError for FileUtils when fileutils isn't already loaded.

    Kenta Ishizaki

  • Fix Enumerable#in_order_of with filter: true dropping nil elements explicitly named in the series.

    Kenta Ishizaki

  • Keep HashWithIndifferentAccess#filter returning a HashWithIndifferentAccess instead of a plain Hash.

    Kenta Ishizaki

  • Fix number_to_human and number_to_human_size crashing when :precision is nil.

    Kenta Ishizaki

  • Fix ActiveSupport::InheritableOptions#to_h to recursively flatten nested InheritableOptions parents.

    Andrew Novoselac

  • Fix ActiveSupport::StructuredEventSubscriber.debug_only leaking debug-only methods across subscriber subclasses.

    Kenta Ishizaki

... (truncated)

Changelog

Sourced from activesupport's changelog.

Rails 8.1.4 (September 24, 2026)

  • Fix the debug error page rendering for SyntaxErrors with multi-line messages.

    Marco Roth

  • Make ActiveSupport::JSON.decode compatible with the upcoming json 3.0 gem.

    Earlopain

  • Fix number_to_human_size crashing for sizes above a terabyte by supporting petabyte, exabyte, and zettabyte storage units.

    Kenta Ishizaki

  • Fix Range#sole raising NoMethodError when the enumerable core extension isn't already loaded.

    Kenta Ishizaki

  • Fix ActiveSupport::Cache::FileStore raising NameError for FileUtils when fileutils isn't already loaded.

    Kenta Ishizaki

  • Fix Enumerable#in_order_of with filter: true dropping nil elements explicitly named in the series.

    Kenta Ishizaki

  • Keep HashWithIndifferentAccess#filter returning a HashWithIndifferentAccess instead of a plain Hash.

    Kenta Ishizaki

  • Fix number_to_human and number_to_human_size crashing when :precision is nil.

    Kenta Ishizaki

  • Fix ActiveSupport::InheritableOptions#to_h to recursively flatten nested InheritableOptions parents.

    Andrew Novoselac

  • Fix ActiveSupport::StructuredEventSubscriber.debug_only leaking debug-only methods across subscriber subclasses.

    Kenta Ishizaki

  • Fix ActiveSupport::Inflector#transliterate mutating the caller's string.

... (truncated)

Commits
  • c3466ea Preparing for 8.1.4 release
  • e6288a8 Update CHANGELOGs for 8-1-stable backports
  • 215952f Merge pull request #58727 from marcoroth/multiline-syntax-errors
  • 6785886 Merge pull request #58688 from byroot/upgrade-rubocop
  • e0d220c Fixed guard around AS::TC.run_order
  • a3bcedd Merge pull request #58639 from moizafzal936/fix-fetch-multi-local-cache-order
  • 5b7765c AS::JSON.decode: handle nil options
  • c8b51db Merge pull request #58601 from Earlopain/json-3.0-compat
  • 888d752 [8-1-stable] Silence Time.rfc3339 redefinition warning
  • c957a6b Merge pull request #58324 from hammadxcm/fix-parameterize-nil-separator
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the bundler-minor-patch group with 4 updates: [actionpack](https://github.com/rails/rails), [activerecord](https://github.com/rails/rails), [railties](https://github.com/rails/rails) and [activesupport](https://github.com/rails/rails).


Updates `actionpack` from 8.1.3.1 to 8.1.4
- [Release notes](https://github.com/rails/rails/releases)
- [Changelog](https://github.com/rails/rails/blob/v8.1.4/actionpack/CHANGELOG.md)
- [Commits](rails/rails@v8.1.3.1...v8.1.4)

Updates `activerecord` from 8.1.3.1 to 8.1.4
- [Release notes](https://github.com/rails/rails/releases)
- [Changelog](https://github.com/rails/rails/blob/v8.1.4/activerecord/CHANGELOG.md)
- [Commits](rails/rails@v8.1.3.1...v8.1.4)

Updates `railties` from 8.1.3.1 to 8.1.4
- [Release notes](https://github.com/rails/rails/releases)
- [Changelog](https://github.com/rails/rails/blob/v8.1.4/railties/CHANGELOG.md)
- [Commits](rails/rails@v8.1.3.1...v8.1.4)

Updates `activesupport` from 8.1.3.1 to 8.1.4
- [Release notes](https://github.com/rails/rails/releases)
- [Changelog](https://github.com/rails/rails/blob/v8.1.4/activesupport/CHANGELOG.md)
- [Commits](rails/rails@v8.1.3.1...v8.1.4)

---
updated-dependencies:
- dependency-name: actionpack
  dependency-version: 8.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bundler-minor-patch
- dependency-name: activerecord
  dependency-version: 8.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bundler-minor-patch
- dependency-name: railties
  dependency-version: 8.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bundler-minor-patch
- dependency-name: activesupport
  dependency-version: 8.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bundler-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, security. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@VSN2015
VSN2015 merged commit b98e277 into master Sep 29, 2026
16 checks passed
@dependabot
dependabot Bot deleted the dependabot/bundler/bundler-minor-patch-726e0fca9f branch September 29, 2026 17:29
VSN2015 pushed a commit that referenced this pull request Sep 29, 2026
Bumps version.rb, adds the 0.10.0 CHANGELOG section, and includes the
regenerated Gemfile.lock — CI runs bundler in frozen mode, so a version bump
without the lockfile fails the tag build.

Eleven PRs since 0.9.0 (#74-#84): numeric strings must be spelled
canonically (no underscore separators or surrounding whitespace), an array
default: runs its sub-fields' transform: so an omitted field and an
explicitly-sent identical value agree, a CSRF param renamed via
request_forgery_protection_token no longer trips unknown: :error, a
sensitive: field's default:/example: are omitted from the exported schema,
message: is deep-frozen like the other authored values, the generator guards
an enum accessor the model lacks and no longer swallows non-ActiveRecord
errors, the error-response and scalar schema constants are handed out as
deep copies, the sensitive-parameter sink list is read under its mutex, and
the Rails dev dependencies move to 8.1.4.

Minor rather than patch: no new surface, but a client sending "1_8" or " 99 "
for a numeric field now gets 422 instead of a number, and a sub-field
transform: now runs over an array default: at class load. See CHANGELOG.md.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant