Sitelet https://github.com/XIVAuth/XIVAuth/pull/36
Skip to content

chore(deps): bump the ruby group across 1 directory with 21 updates - #36

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/ruby-74ff167ed6
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/ruby-74ff167ed6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the ruby group with 21 updates in the / directory:

Package From To
msgpack 1.8.4 1.8.5
redis 5.4.1 6.0.0
aws-sdk-s3 1.229.0 1.232.0
image_processing 2.0.3 2.1.0
bootsnap 1.25.0 1.26.0
sidekiq 8.1.6 8.1.7
devise-two-factor 6.4.0 6.4.1
doorkeeper 5.9.6 5.9.7
jwt 3.2.0 3.3.0
rails_cloudflare_turnstile 0.5.0 0.5.1
faraday 2.14.3 2.14.4
rails_semantic_logger 5.1.0 5.2.0
sentry-rails 6.7.0 7.0.0
sentry-ruby 6.7.0 7.0.0
sentry-sidekiq 6.7.0 7.0.0
rubocop 1.89.0 1.91.0
sentry-ruby 6.7.0 7.0.0
sentry-sidekiq 6.7.0 7.0.0
meta-tags 2.23.0 2.24.0
pagy 43.6.1 43.6.2
simplecov 1.1.1 1.3.0
rubocop 1.89.0 1.91.0
rack-mini-profiler 4.0.1 5.0.0
selenium-webdriver 4.47.0 4.49.0

Updates msgpack from 1.8.4 to 1.8.5

Changelog

Sourced from msgpack's changelog.

2026-09-11 1.8.5

  • Prevent stack depth underflow when skipping from recursive unpacker.
  • Fix Unpacker#skip_nil to properly consume the buffer.
  • Fix some small difference in Factory registration of the Java implementation.
  • Fix some Factory/ext_type optimization edge cases.
Commits
  • 972321a Release 1.8.5
  • db16d5d Merge pull request #406 from youdie006/symbol-unpacker-only-npe
  • 72cda9b Guard packerProc against a missing :packer key on JRuby
  • 4e2a755 Merge pull request #405 from Watson1978/fix/recursive-ext-stack-underflow
  • 7ff80ad Fix SEGV on stack depth underflow in recursive extension unpacking
  • 29d98d3 Merge pull request #403 from OskarEichler/audit/factory-registration-edge-cases
  • 663c3a3 Merge pull request #404 from OskarEichler/audit/consume-skip-nil
  • 512b587 Consume nil in Unpacker#skip_nil
  • c3d1c61 Fix Factory registration edge cases
  • 8c429cd Merge pull request #402 from msgpack/gc-guard
  • Additional commits viewable in compare view

Updates redis from 5.4.1 to 6.0.0

Release notes

Sourced from redis's releases.

6.0.0

This is a major release of the redis and redis-clustering gems. The headline change is that the client now speaks RESP3 by default, alongside first-class support for the Redis Query Engine and the JSON module, a batch of new Redis 6.2–8.10 commands, and experimental support for the Redis 8.10 HIMPORT bulk-ingestion command family.

Command return values are unchanged from 5.x with one exception (GEO coordinates, see below), so for most applications this upgrade is a Gemfile bump.

Requires Ruby 3.2+ and works with Redis server 6.0+ (older servers are handled via automatic RESP2 fallback).

RESP3 by default

RESP3's richer wire types (native maps, doubles, booleans) let the parser deliver replies already in their final Ruby shape. Under RESP2, structured replies arrive as flat arrays of bulk strings that the client must re-shape in Ruby — e.g. HGETALL builds a Hash from a flat [field, value, ...] array, and sorted-set scores are converted String → Float pair by pair. Under RESP3 that re-shaping pass disappears.

Measured with bench/resp_comparison.rb (redis-rb 6.0.0, Ruby 3.4.1, Redis 8.8, localhost, 100-element replies):

Pure-Ruby driver (default):

Workload RESP2 → RESP3 RPS (8 threads) RESP2 → RESP3 µs CPU/op
GET (50B string) 4251 → 4436 (+4%) 23.4 → 22.9 (~0)
HGETALL (100 fields) 2361 → 2560 (+8%) 164 → 129 (−22%)
ZRANGE WITHSCORES (100) 2597 → 2459 (−5%) 130 → 147 (~0, noise)
XRANGE (100 entries) 1544 → 1570 (+2%) 346 → 328 (~0)

hiredis driver (C parser):

Workload RESP2 → RESP3 RPS (8 threads) RESP2 → RESP3 µs CPU/op
GET 12756 → 12620 (~0) 69 → 70 (~0)
HGETALL 10175 → 10592 (+4%) 97 → 89 (−8%; 1 thread: 88 → 63, −28%)
ZRANGE WITHSCORES 10036 → 11629 (+16%) 108 → 85 (−22%)
XRANGE 7053 → 6999 (~0) 152 → 152 (~0)

In short: hash reads use ~10–25% less client CPU per call on both drivers; sorted-set reads with scores gain up to 16% throughput and ~20% less CPU with hiredis (unchanged on the pure-Ruby driver, where parsing RESP3 doubles costs roughly what the re-shaping pass did); simple string and stream commands are unaffected — their reply shapes are the same in both protocols. RESP3 pairs best with the hiredis driver, which moves all reply construction out of Ruby and into C.

Methodology note: figures are per-reply CPU measurements against a localhost server; wall-clock throughput gains in production depend on how network-bound your workload is.

Beyond performance, RESP3 also lays the groundwork for push-based features — such as server-assisted client-side caching (CLIENT TRACKING invalidation events) — in future 6.x releases, without another protocol migration.

🔥 Breaking changes

  • RESP3 by default (see above); pass protocol: 2 to keep RESP2. The only return-value change is GEO coordinates as Float. (#1351)
  • Requires Ruby 3.2+ (previously 2.7/2.6). Bundler will keep older Rubies on the 5.4.x series automatically. (#1353, #1365)

Cluster gem (redis-clustering) only

  • Commands are now routed by their server-declared command tips (redis-cluster-client 0.16.6+): SLOWLOG GET returns one entry list per master; SLOWLOG LEN and LATENCY RESET return the sum across all masters; FUNCTION LOAD/DELETE/FLUSH/RESTORE now execute on all masters (previously a single arbitrary node — this also fixes FCALL failing for keys on other masters); commands with keys in subcommands (e.g. XINFO STREAM) route to the key's slot owner.

🚀 New features

  • Redis Query Engine (RediSearch, FT.*): ft_create, ft_alter, ft_dropindex, ft_info, ft_search, ft_aggregate, vector and hybrid search, suggestions, dictionaries, synonyms, aliases, and spellcheck. Not supported by Redis::Distributed. (#1356, #1359, #1360, #1361)
  • JSON module: json_set, json_get, json_mset, json_mget, json_del, json_forget, json_clear, json_merge, json_arr*, json_obj*, json_str*, json_numincrby, json_toggle, json_type, json_debug_memory. (#1346, #1347, #1348, #1349)

... (truncated)

Changelog

Sourced from redis's changelog.

6.0.0

Breaking changes

New features

  • Add support for the Redis Query Engine (RediSearch, FT.*): ft_create, ft_alter, ft_dropindex, ft_info, ft_search, ft_aggregate, vector and hybrid search, suggestions, dictionaries, synonyms, aliases, and spellcheck. Not supported by Redis::Distributed. (#1356, #1359, #1360, #1361)
  • Add support for the JSON module: json_set, json_get, json_mset, json_mget, json_del, json_forget, json_clear, json_merge, json_arr*, json_obj*, json_str*, json_numincrby, json_toggle, json_type, json_debug_memory. (#1346, #1347, #1348, #1349)
  • Add keyspace notification support: channel builders and a binary-safe parser for the classic __keyspace@*/__keyevent@* channels and the Redis 8.8 subkey notification families (Redis::KeyspaceNotifications), plus a manager (Redis#keyspace_notifications) that owns a dedicated connection, dispatches typed Notification objects to handlers, and automatically re-subscribes after connection loss (on_reconnect signals the lossy gap). Enabling notify-keyspace-events on the server remains the operator's responsibility. Not supported by Redis::Distributed. See specs/keyspace-notifications/user-guide.md.
  • Add lmovem and blmovem (Redis 8.10). (#1363)
  • Add sunioncard and sdiffcard (Redis 8.10). (#1357)
  • xread and xreadgroup now accept max_count: and max_size: (Redis 8.10). (#1358)
  • Add hexpire, hpexpire, httl and hpttl (Redis 7.4). (#1324, #1325, #1331)
  • Add hexpireat, hpexpireat, hexpiretime, hpexpiretime and hpersist; hexpire and hpexpire now accept the nx:/xx:/gt:/lt: condition options (Redis 7.4). All are available on Redis::Distributed. (#1374)
  • hscan and hscan_each now accept novalues: true (Redis 7.4). (#1327)
  • Add geosearch and geosearchstore (Redis 6.2); geo commands are now available on Redis::Distributed. (#1342)
  • geoadd now accepts nx:, xx: and ch:; geo radius searches accept count_any:; xadd accepts limit: (Redis 6.2). (#1345)
  • Redis::Distributed now implements hscan, hscan_each and hstrlen. (#1319)
  • Identify the client to the server via CLIENT SETINFO (lib-name=redis-rb, lib-ver=<version>). Extend the reported name with driver_info:, or disable with driver_info: false. See the README "Client identification" section. (#1369)

Experimental

  • Add himport_prepare, himport_set, himport_discard and himport_discard_all (Redis 8.10 HIMPORT). Lost fieldsets are re-prepared and retried automatically; disable with himport_auto_prepare: false. The API may change in a future minor release. See the README "Bulk hash ingestion (HIMPORT)" section. (#1364)

Bug fixes

... (truncated)

Commits

Updates aws-sdk-s3 from 1.229.0 to 1.232.0

Changelog

Sourced from aws-sdk-s3's changelog.

1.232.0 (2026-09-11)

  • Feature - Updated S3 Object Lock Default Retention documentation.

1.231.0 (2026-09-09)

  • Feature - Code Generated Changes, see ./build_tools or aws-sdk-core's CHANGELOG.md for details.

1.230.0 (2026-09-08)

  • Feature - Adds support for Amazon S3 Object Lock variable retention. Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level.
Commits

Updates image_processing from 2.0.3 to 2.1.0

Changelog

Sourced from image_processing's changelog.

2.1.0 (2026-09-01)

  • [minimagick] Add inherit_fds: so a loader can name an already-open input (thanks to @​flavorjones)
Commits

Updates bootsnap from 1.25.0 to 1.26.0

Release notes

Sourced from bootsnap's releases.

v1.26.0

What's Changed

  • Handle top level Coverage constant being defined, but without it being the true stdlib coverage module.
  • Fix bootsnap precompile that could generate a corrupted cache entry if an already cached YAML file was modified without changing its size.
  • Workaround a potential Ruby SEGV if Bootsnap.instrumentation raised an error.
Changelog

Sourced from bootsnap's changelog.

1.26.0

  • Handle top level Coverage constant being defined, but without it being the true stdlib coverage module.
  • Fix bootsnap precompile that could generate a corrupted cache entry if an already cached YAML file was modified without changing its size.
  • Workaround a potential Ruby SEGV if Bootsnap.instrumentation raised an error.
Commits
  • 67a7290 Release 1.26.0
  • 1881b9a Merge pull request #573 from byroot/same-size-miscompilation
  • 605bbeb Fix precompilation when regenerating an existing cache entry of the same size
  • 5fd59da Merge pull request #569 from OskarEichler/codex/accept-tempfile-fd-zero
  • 70550c7 Merge pull request #568 from OskarEichler/codex/remove-umask-debug-output
  • 8aed2ed Accept tempfile descriptor zero
  • f7457ea Remove umask debug output
  • 9ee62a2 Merge pull request #567 from byroot/rename-mod
  • 7c8178e Handle write(2) being interrupted.
  • 3e755ca atomic_write_cache_file: stop leaking FD on error
  • Additional commits viewable in compare view

Updates sidekiq from 8.1.6 to 8.1.7

Changelog

Sourced from sidekiq's changelog.

8.1.7

  • Forward compatibililty with Active Job 8.1 #7019
  • Many minor fixes and test improvements [hammadxcm]
Commits

Updates devise-two-factor from 6.4.0 to 6.4.1

Changelog

Sourced from devise-two-factor's changelog.

6.4.1

  • Update gem spec metadata sourcecode URI
Commits
  • 5e74a93 Bump to v6.4.1
  • 68f93e6 Set source_code_uri gemspec metadata to homepage
  • 1f557e6 Merge pull request #326 from connorshea/patch-2
  • 8e6717c Update email link format for vulnerability reporting
  • 120ae1f Merge pull request #325 from connorshea/connorshea-patch-1
  • cf0e079 Run bundle install in gem push workflow
  • b889f1d Merge pull request #324 from connorshea/patch-1
  • 475e34c Remove bundler-cache from Ruby setup in release job
  • 8262ce0 Create ISSUE_TEMPLATE/config.yml
  • See full diff in compare view

Updates doorkeeper from 5.9.6 to 5.9.7

Release notes

Sourced from doorkeeper's releases.

v5.9.7

  • Refuse requests that transmit an access token by more than one method (RFC 6750 §2), instead of silently authorizing with the first configured access_token_methods entry that matched and discarding the other tokens. Such a request now fails closed as carrying no usable token (401 invalid_token); no calling contract changes. The form-encoded body (§2.2) and the URI query (§2.3) count as two methods even though Rails and Rack merge them into a single params hash. The same token repeated across two methods is refused too — §2 forbids the second method, not a disagreement between the two — and a custom callable extractor in access_token_methods keeps the historical first-wins behavior and is never invoked more than once. (The strict invalid_request (400) answer §3.1 prescribes ships with Doorkeeper 6.0.)
  • #1925 Internal: pin the development dependency on json below 3.0. json 3 removed the positional options Hash from JSON.parse and the quirks_mode option from JSON.generate, both of which Active Support still uses, so the suite could not run on any supported Rails version.
Changelog

Sourced from doorkeeper's changelog.

5.9.7

  • Refuse requests that transmit an access token by more than one method (RFC 6750 §2), instead of silently authorizing with the first configured access_token_methods entry that matched and discarding the other tokens. Such a request now fails closed as carrying no usable token (401 invalid_token); no calling contract changes. The form-encoded body (§2.2) and the URI query (§2.3) count as two methods even though Rails and Rack merge them into a single params hash. The same token repeated across two methods is refused too — §2 forbids the second method, not a disagreement between the two — and a custom callable extractor in access_token_methods keeps the historical first-wins behavior and is never invoked more than once. (The strict invalid_request (400) answer §3.1 prescribes ships with Doorkeeper 6.0.)
  • #1925 Internal: pin the development dependency on json below 3.0. json 3 removed the positional options Hash from JSON.parse and the quirks_mode option from JSON.generate, both of which Active Support still uses, so the suite could not run on any supported Rails version.
Commits
  • bc75190 Merge pull request #1929 from doorkeeper-gem/chore/bump-5.9.7
  • 49dcb5b Release 5.9.7
  • fcc425c Pin the development dependency on json below 3.0
  • a6d4128 Merge commit from fork
  • df59bd5 Refuse a request that transmits an access token by more than one method
  • See full diff in compare view

Updates jwt from 3.2.0 to 3.3.0

Changelog

Sourced from jwt's changelog.

v3.3.0 (2026-09-11)

Full Changelog

Features:

Fixes and enhancements:

  • Refactor JWT::JWK::Set#initialize so each construction path is a named method #758 (@​anakinj)
  • Fix rejection of unknown algorithms from JWKs for RFC compliance and pquip #728
  • Fix the Style/DirectiveScope RuboCop offense failing the build #752
  • Fix JWT::JWK::Set sharing its key collection with the set it was copied from #751
  • Reset the decoded payload and verification state in JWT::EncodedToken#encoded_payload= #749
  • Fix JWT::Token#detach_payload! not invalidating an already rendered token #748
Commits
  • ccf2489 Prepare the v3.3.0 release (#762)
  • 6cdacc3 Enforce parentheses on method calls with arguments (#761)
  • 4a576f8 Declutter jwt_spec.rb (#760)
  • 7ddcb0a Fix the RSA-PSS guard skipping the whole jwt_spec file (#759)
  • 7cede0c Refactor JWT::JWK::Set#initialize (#758)
  • 6ab1be7 Revamp error hierarchy (#722)
  • 41fbf31 Invalidate the rendered token when detaching the payload (#757)
  • d8e231d Reset verification state when replacing the encoded payload (#756)
  • c25fb5e Fix JWT::JWK::Set sharing its key collection when copied (#751)
  • bec0ffd Isolate gem builds from release credentials (#755)
  • Additional commits viewable in compare view

Updates rails_cloudflare_turnstile from 0.5.0 to 0.5.1

Release notes

Sourced from rails_cloudflare_turnstile's releases.

v0.5.1

What's Changed

New Contributors

Full Changelog: instrumentl/rails-cloudflare-turnstile@v0.5.0...v0.5.1

Changelog

Sourced from rails_cloudflare_turnstile's changelog.

0.5.1

  • Ruby 4.0 support added.
  • Dependencies updates
Commits
  • 35bd12e feat: add ruby 4.0 support and release 0.5.1 (#281)
  • bf25fa5 chore(deps-dev): bump sqlite3 from 2.9.5 to 2.9.6 (#280)
  • a448a38 fix: bump rails to 8.1.3.1 to address cve-2026-66066 (#279)
  • 55f3ae0 chore(deps): bump actions/setup-python from 6 to 7 (#277)
  • 08443bf chore(deps-dev): bump standard from 1.55.0 to 1.56.0 (#276)
  • b232880 chore: update loofah, rails-html-sanitizer, websocket-driver (#278)
  • b894a11 chore(deps): bump actions/checkout from 6 to 7 (#275)
  • 6f97162 chore(deps-dev): bump standard from 1.54.0 to 1.55.0 (#274)
  • ce3d116 feat: add **html_options (e.g. CSP nonce) support to cloudflare_turnstile_scr...
  • 55216e0 chore: resolve net-imap CVEs (#273)
  • Additional commits viewable in compare view

Updates faraday from 2.14.3 to 2.14.4

Release notes

Sourced from faraday's releases.

v2.14.4

What's Changed

New Contributors

Full Changelog: lostisland/faraday@v2.14.3...v2.14.4

Commits

Updates rails_semantic_logger from 5.1.0 to 5.2.0

Changelog

Sourced from rails_semantic_logger's changelog.

[5.2.0] - 2026-09-05

  • Deprecations: the gem's deprecator is now registered as Rails.application.deprecators[:rails_semantic_logger], so the application's own deprecation settings govern it: config.active_support.report_deprecations = false, config.active_support.deprecation = :raise, or silencing that one deprecator by name. Rails' active_support.deprecation_behavior initializer only reaches deprecators in that collection, and this one was never added to it, so nothing an application configured could reach the warnings. Note that an application still setting deprecated options will now see them raise under config.active_support.deprecation = :raise.
  • Deprecations: the warnings for the deprecated appender options (format, ap_options, filter, console_logger, add_file_appender) are no longer emitted from the setter. Those options are documented to be set in config/application.rb or config/environments/*.rb, which Rails reads in load_environment_config, long before active_support.deprecation_behavior applies the settings above, so warning from the setter landed in a window that no application configuration could reach. The warnings are now recorded and emitted once Rails has applied that configuration. Each option is reported once per boot, attributed to the first place it was set; options set later (from config/initializers/*, or at runtime) still warn immediately at their call site. Fixes #328.
  • ActionCable: resolve the TaggedLoggerProxy class at runtime instead of requiring it by path. Rails 8.2 moves it from ActionCable::Connection::TaggedLoggerProxy to ActionCable::Server::TaggedLoggerProxy, as part of the ActionCable::Server::Socket refactor, and leaves no back-compat alias, so the unconditional require "action_cable/connection/tagged_logger_proxy" raised LoadError during after_initialize and failed the app's boot on Rails edge. Fixes #326.
  • Documentation: the Semantic Logger documentation site has moved from logger.rocketjob.io to logger.reidmorrison.com. The gem's homepage and documentation_uri metadata now point there, as do the links in the README.
Commits
  • 5d718dd Merge pull request #330 from reidmorrison/v5.2
  • 50aea8f Release v5.2.0
  • 674e03d Additional tests
  • 131b188 Merge pull request #329 from reidmorrison/fix/register-deprecator-and-defer-w...
  • 2d15e8d Register the deprecator and defer the appender-option warnings
  • e55daab Merge pull request #327 from reidmorrison/fix/action-cable-tagged-logger-prox...
  • 1e8d3b3 Resolve the ActionCable TaggedLoggerProxy class at runtime
  • 66fa299 Merge pull request #325 from reidmorrison/docs/update-doc-site-domain
  • 5879aa7 Point documentation links at logger.reidmorrison.com
  • See full diff in compare view

Updates sentry-rails from 6.7.0 to 7.0.0

Changelog

Sourced from sentry-rails's changelog.

7.0.0

Breaking Changes 🛠

  • Logs are now enabled by default and enable_logs is removed. by @​sl0thentr0py in #3053

    Using sentry-rails will automatically turn on automatic structured logging from Rails. if you want to turn it off, use:

    Sentry.init do |config|
      # ...
      config.rails.structured_logging.enabled = false
    end
  • Metrics are now enabled by default and enable_metrics is removed. by @​sl0thentr0py in #3061

  • config.otlp.setup_otlp_traces_exporter and config.otlp.setup_propagator now default to false. by @​sl0thentr0py in #3063

New Features ✨

Data Collection

We are moving away from send_default_pii to a more granular configuration called data_collection.
It allows you to precisely control the data that Sentry collects from your app.

Sentry.init do |config|
  # ...
  config.data_collection.user_info = false
  config.data_collection.http_bodies = []
end

send_default_pii is deprecated but will con...

Description has been truncated

Bumps the ruby group with 21 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [msgpack](https://github.com/msgpack/msgpack-ruby) | `1.8.4` | `1.8.5` |
| [redis](https://github.com/redis/redis-rb) | `5.4.1` | `6.0.0` |
| [aws-sdk-s3](https://github.com/aws/aws-sdk-ruby) | `1.229.0` | `1.232.0` |
| [image_processing](https://github.com/janko/image_processing) | `2.0.3` | `2.1.0` |
| [bootsnap](https://github.com/rails/bootsnap) | `1.25.0` | `1.26.0` |
| [sidekiq](https://github.com/sidekiq/sidekiq) | `8.1.6` | `8.1.7` |
| [devise-two-factor](https://github.com/devise-two-factor/devise-two-factor) | `6.4.0` | `6.4.1` |
| [doorkeeper](https://github.com/doorkeeper-gem/doorkeeper) | `5.9.6` | `5.9.7` |
| [jwt](https://github.com/jwt/ruby-jwt) | `3.2.0` | `3.3.0` |
| [rails_cloudflare_turnstile](https://github.com/instrumentl/rails-cloudflare-turnstile) | `0.5.0` | `0.5.1` |
| [faraday](https://github.com/lostisland/faraday) | `2.14.3` | `2.14.4` |
| [rails_semantic_logger](https://github.com/reidmorrison/rails_semantic_logger) | `5.1.0` | `5.2.0` |
| [sentry-rails](https://github.com/getsentry/sentry-ruby) | `6.7.0` | `7.0.0` |
| [sentry-ruby](https://github.com/getsentry/sentry-ruby) | `6.7.0` | `7.0.0` |
| [sentry-sidekiq](https://github.com/getsentry/sentry-ruby) | `6.7.0` | `7.0.0` |
| [rubocop](https://github.com/rubocop/rubocop) | `1.89.0` | `1.91.0` |
| [sentry-ruby](https://github.com/getsentry/sentry-ruby) | `6.7.0` | `7.0.0` |
| [sentry-sidekiq](https://github.com/getsentry/sentry-ruby) | `6.7.0` | `7.0.0` |
| [meta-tags](https://github.com/kpumuk/meta-tags) | `2.23.0` | `2.24.0` |
| [pagy](https://github.com/ddnexus/pagy) | `43.6.1` | `43.6.2` |
| [simplecov](https://github.com/simplecov-ruby/simplecov) | `1.1.1` | `1.3.0` |
| [rubocop](https://github.com/rubocop/rubocop) | `1.89.0` | `1.91.0` |
| [rack-mini-profiler](https://github.com/MiniProfiler/rack-mini-profiler) | `4.0.1` | `5.0.0` |
| [selenium-webdriver](https://github.com/SeleniumHQ/selenium) | `4.47.0` | `4.49.0` |



Updates `msgpack` from 1.8.4 to 1.8.5
- [Changelog](https://github.com/msgpack/msgpack-ruby/blob/master/ChangeLog)
- [Commits](msgpack/msgpack-ruby@v1.8.4...v1.8.5)

Updates `redis` from 5.4.1 to 6.0.0
- [Release notes](https://github.com/redis/redis-rb/releases)
- [Changelog](https://github.com/redis/redis-rb/blob/master/CHANGELOG.md)
- [Commits](redis/redis-rb@v5.4.1...v6.0.0)

Updates `aws-sdk-s3` from 1.229.0 to 1.232.0
- [Release notes](https://github.com/aws/aws-sdk-ruby/releases)
- [Changelog](https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sdk-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-ruby/commits)

Updates `image_processing` from 2.0.3 to 2.1.0
- [Changelog](https://github.com/janko/image_processing/blob/master/CHANGELOG.md)
- [Commits](janko/image_processing@v2.0.3...v2.1.0)

Updates `bootsnap` from 1.25.0 to 1.26.0
- [Release notes](https://github.com/rails/bootsnap/releases)
- [Changelog](https://github.com/rails/bootsnap/blob/main/CHANGELOG.md)
- [Commits](rails/bootsnap@v1.25.0...v1.26.0)

Updates `sidekiq` from 8.1.6 to 8.1.7
- [Changelog](https://github.com/sidekiq/sidekiq/blob/main/Changes.md)
- [Commits](sidekiq/sidekiq@v8.1.6...v8.1.7)

Updates `devise-two-factor` from 6.4.0 to 6.4.1
- [Release notes](https://github.com/devise-two-factor/devise-two-factor/releases)
- [Changelog](https://github.com/devise-two-factor/devise-two-factor/blob/main/CHANGELOG.md)
- [Commits](devise-two-factor/devise-two-factor@v6.4.0...v6.4.1)

Updates `doorkeeper` from 5.9.6 to 5.9.7
- [Release notes](https://github.com/doorkeeper-gem/doorkeeper/releases)
- [Changelog](https://github.com/doorkeeper-gem/doorkeeper/blob/main/CHANGELOG.md)
- [Commits](doorkeeper-gem/doorkeeper@v5.9.6...v5.9.7)

Updates `jwt` from 3.2.0 to 3.3.0
- [Release notes](https://github.com/jwt/ruby-jwt/releases)
- [Changelog](https://github.com/jwt/ruby-jwt/blob/main/CHANGELOG.md)
- [Commits](jwt/ruby-jwt@v3.2.0...v3.3.0)

Updates `rails_cloudflare_turnstile` from 0.5.0 to 0.5.1
- [Release notes](https://github.com/instrumentl/rails-cloudflare-turnstile/releases)
- [Changelog](https://github.com/instrumentl/rails-cloudflare-turnstile/blob/main/CHANGELOG.md)
- [Commits](instrumentl/rails-cloudflare-turnstile@v0.5.0...v0.5.1)

Updates `faraday` from 2.14.3 to 2.14.4
- [Release notes](https://github.com/lostisland/faraday/releases)
- [Changelog](https://github.com/lostisland/faraday/blob/main/CHANGELOG.md)
- [Commits](lostisland/faraday@v2.14.3...v2.14.4)

Updates `rails_semantic_logger` from 5.1.0 to 5.2.0
- [Changelog](https://github.com/reidmorrison/rails_semantic_logger/blob/main/CHANGELOG.md)
- [Commits](reidmorrison/rails_semantic_logger@v5.1.0...v5.2.0)

Updates `sentry-rails` from 6.7.0 to 7.0.0
- [Release notes](https://github.com/getsentry/sentry-ruby/releases)
- [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-ruby@6.7.0...7.0.0)

Updates `sentry-ruby` from 6.7.0 to 7.0.0
- [Release notes](https://github.com/getsentry/sentry-ruby/releases)
- [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-ruby@6.7.0...7.0.0)

Updates `sentry-sidekiq` from 6.7.0 to 7.0.0
- [Release notes](https://github.com/getsentry/sentry-ruby/releases)
- [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-ruby@6.7.0...7.0.0)

Updates `rubocop` from 1.89.0 to 1.91.0
- [Release notes](https://github.com/rubocop/rubocop/releases)
- [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.md)
- [Commits](rubocop/rubocop@v1.89.0...v1.91.0)

Updates `sentry-ruby` from 6.7.0 to 7.0.0
- [Release notes](https://github.com/getsentry/sentry-ruby/releases)
- [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-ruby@6.7.0...7.0.0)

Updates `sentry-sidekiq` from 6.7.0 to 7.0.0
- [Release notes](https://github.com/getsentry/sentry-ruby/releases)
- [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-ruby@6.7.0...7.0.0)

Updates `meta-tags` from 2.23.0 to 2.24.0
- [Release notes](https://github.com/kpumuk/meta-tags/releases)
- [Changelog](https://github.com/kpumuk/meta-tags/blob/main/CHANGELOG.md)
- [Commits](kpumuk/meta-tags@v2.23.0...v2.24.0)

Updates `pagy` from 43.6.1 to 43.6.2
- [Release notes](https://github.com/ddnexus/pagy/releases)
- [Changelog](https://github.com/ddnexus/pagy/blob/master/docs/CHANGELOG.md)
- [Commits](ddnexus/pagy@43.6.1...43.6.2)

Updates `simplecov` from 1.1.1 to 1.3.0
- [Release notes](https://github.com/simplecov-ruby/simplecov/releases)
- [Changelog](https://github.com/simplecov-ruby/simplecov/blob/main/CHANGELOG.md)
- [Commits](simplecov-ruby/simplecov@v1.1.1...v1.3.0)

Updates `rubocop` from 1.89.0 to 1.91.0
- [Release notes](https://github.com/rubocop/rubocop/releases)
- [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.md)
- [Commits](rubocop/rubocop@v1.89.0...v1.91.0)

Updates `rack-mini-profiler` from 4.0.1 to 5.0.0
- [Release notes](https://github.com/MiniProfiler/rack-mini-profiler/releases)
- [Changelog](https://github.com/MiniProfiler/rack-mini-profiler/blob/master/CHANGELOG.md)
- [Commits](MiniProfiler/rack-mini-profiler@v4.0.1...v5.0.0)

Updates `selenium-webdriver` from 4.47.0 to 4.49.0
- [Release notes](https://github.com/SeleniumHQ/selenium/releases)
- [Changelog](https://github.com/SeleniumHQ/selenium/blob/trunk/rb/CHANGES)
- [Commits](SeleniumHQ/selenium@selenium-4.47.0...selenium-4.49.0)

---
updated-dependencies:
- dependency-name: msgpack
  dependency-version: 1.8.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby
- dependency-name: redis
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ruby
- dependency-name: aws-sdk-s3
  dependency-version: 1.232.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby
- dependency-name: image_processing
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby
- dependency-name: bootsnap
  dependency-version: 1.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby
- dependency-name: sidekiq
  dependency-version: 8.1.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby
- dependency-name: devise-two-factor
  dependency-version: 6.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby
- dependency-name: doorkeeper
  dependency-version: 5.9.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby
- dependency-name: jwt
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby
- dependency-name: rails_cloudflare_turnstile
  dependency-version: 0.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby
- dependency-name: faraday
  dependency-version: 2.14.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby
- dependency-name: rails_semantic_logger
  dependency-version: 5.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby
- dependency-name: sentry-rails
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ruby
- dependency-name: sentry-ruby
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ruby
- dependency-name: sentry-sidekiq
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ruby
- dependency-name: rubocop
  dependency-version: 1.91.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: ruby
- dependency-name: sentry-ruby
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ruby
- dependency-name: sentry-sidekiq
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ruby
- dependency-name: meta-tags
  dependency-version: 2.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby
- dependency-name: pagy
  dependency-version: 43.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby
- dependency-name: simplecov
  dependency-version: 1.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: ruby
- dependency-name: rubocop
  dependency-version: 1.91.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: ruby
- dependency-name: rack-mini-profiler
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: ruby
- dependency-name: selenium-webdriver
  dependency-version: 4.49.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: ruby
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 19, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 26, 2026
@dependabot
dependabot Bot deleted the dependabot/bundler/ruby-74ff167ed6 branch September 26, 2026 02:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants