Update ruby dependencies (non-major) to v4.1.3 - #286
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/ruby-dependencies-(non-major)
branch
2 times, most recently
from
September 9, 2026 18:07
71da5d1 to
383a468
Compare
renovate
Bot
force-pushed
the
renovate/ruby-dependencies-(non-major)
branch
from
September 10, 2026 18:48
383a468 to
3fe1971
Compare
renovate
Bot
force-pushed
the
renovate/ruby-dependencies-(non-major)
branch
from
September 13, 2026 13:08
3fe1971 to
27867af
Compare
renovate
Bot
force-pushed
the
renovate/ruby-dependencies-(non-major)
branch
3 times, most recently
from
September 18, 2026 00:13
0609c5a to
8dc1ee9
Compare
renovate
Bot
force-pushed
the
renovate/ruby-dependencies-(non-major)
branch
from
September 24, 2026 23:52
8dc1ee9 to
7082d68
Compare
renovate
Bot
force-pushed
the
renovate/ruby-dependencies-(non-major)
branch
from
September 28, 2026 22:43
7082d68 to
841df9a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.1.2→4.1.39.1.0→9.1.110.7.1→10.9.01.90.0→1.91.04.48.0→4.49.01.3.0→1.3.13.0.0→3.1.0Release Notes
mongodb/mongoid (mongoid)
v9.1.1: 9.1.1Compare Source
The MongoDB Ruby team is pleased to announce version 9.1.1 of the
mongoidgem - a Ruby ODM for MongoDB. This is a new patch release in the 9.1.x series of Mongoid.Install this release using RubyGems via the command line as follows:
Or simply add it to your
Gemfile:Have any feedback? Click on through to MongoDB's Jira and open a new ticket to let us know what's on your mind.
Bug Fixes
Bound regular-expression execution time in in-memory queries (MONGOID-5981) (CVE-2026-93761)
Queries evaluated in memory, such as those against embedded associations, run in the calling thread and can spend an unbounded amount of CPU matching regular expressions. A single in-memory query is now limited by
Mongoid.in_memory_regexp_time_limit(default5.0seconds); exceeding the limit raisesMongoid::Errors::InMemoryRegexpTimeout.Fix encryption schema generation for automatic encryption (MONGOID-5984) (MONGOID-5989) (CVE-2026-93764) (CVE-2026-93763)
Automatic encryption schema generation no longer loops on models that embed themselves, and it now handles polymorphic
embeds_onerelations and embedded schemas that carry their ownencryptMetadatacorrectly. A model whose collection has no entry in the generated schema is no longer written without encryption: such a write raisesMongoid::Errors::NoEncryptionSchemainstead of storing the field in plaintext.Resolve nested attribute ids within the caller's association (MONGOID-5992) (CVE-2026-93758)
An id given in nested attributes is now resolved within the association the attributes are being applied to, rather than falling back to a collection-wide lookup that ignored default scopes. A document that is not part of that association raises
Mongoid::Errors::DocumentNotFound, and a request to destroy a document that is not in the association is ignored. TheMongoid.allow_reparenting_via_nested_attributesoption now defaults tofalse; set it totrueto restore the previous reparenting behavior.Reject the string form of where under the query operator guard (MONGOID-5993) (CVE-2026-93759)
A String passed to
#whereis sent to MongoDB as a$whereexpression. This now raisesMongoid::Errors::InvalidQuerywhenMongoid.allow_unsafe_query_operatorsisfalse(the default); the string form is allowed only when that option is enabled.Reject JavaScript query operators at any depth (MONGOID-5994) (CVE-2026-93760)
Mongoid.allow_unsafe_query_operatorsnow defaults tofalse. When it isfalse, the$where,$function, and$accumulatoroperators are rejected anywhere in a query selector. The guard covers every criterion-building method (where,find_by,or,and,nor,not,any_of,none_of, andelem_match) and inspects nested expressions such as{'$expr' => {'$function' => ...}}in full.Other Bug Fixes
newrelic/newrelic-ruby-agent (newrelic_rpm)
v10.9.0Compare Source
Feature: Continuous Profiling (preview)
Continuous Profiling is a new feature which is not yet generally available for use. The agent-side component code is now present in the agent but to actually use it ahead of the General Availability release, you will need to contact your New Relic sales representative to join the preview early.
Continuous Profiling repeatedly samples the Ruby call stacks of your running application and reports them to New Relic, so you can see which methods are consuming the most CPU time (or allocating the most objects) in production, without adding code to your app.
To turn it on, add the
stackprofandgoogle-protobufgems to your application'sGemfile, then setprofiling.enabledtotrue:With only
profiling.enabledset, the agent samples CPU time every 10 milliseconds for the life of the process. These options let you tune that behavior:falsetrue, the agent collects and reports continuous profiling data.cpucpufor CPU time, orobjectfor object allocations.0.01profiling.includeiscpu. Must be between 0.000001 and 0.999999.10000profiling.includeisobject. Must be between 1000 and 999999.00starts immediately.00profiles until the process exits.PR#3617
Feature: Add support for Dalli 5.1.1
Dalli 5.1.1 added arguments to some of the methods the agent instruments, which could raise an
ArgumentErroron multi-key operations or cause request options to be silently dropped. Now, the agent accepts and forwards a variable number of positional and keyword arguments for these methods. PR#3683v10.8.0Compare Source
Feature: Report a unique hostname for Google Cloud Run Worker Pools and Jobs
The Cloud Run hostname support added in PR#3609 detected Cloud Run by looking for
K_REVISION, which Cloud Run Services set. The agent now also recognizesCLOUD_RUN_REVISION(Worker Pools) andCLOUD_RUN_EXECUTION(Jobs), soutilization.gcp_cloud_run.use_instance_as_hostapplies to all three resource types. Whenutilization.gcp_cloud_run.include_revision_in_hostistrue, the hostname uses whichever of those variables is set, for example{CLOUD_RUN_EXECUTION}-{instance id}on a Job. Issue#3651 Thanks to @choznerol for contributing this enhancement! PR#3652Feature: Add
browser_monitoring.versionconfiguration optionCustomers can now pin the exact browser agent loader version New Relic injects by setting the new
browser_monitoring.versionconfiguration option. See the browser agent EOL policy for which versions are currently available and supported.Feature: Add span.kind to background job libraries
Now, the
span.kindattribute will be added toproduceandconsumeoperations from background job libraries. This includes ActiveJob, Sidekiq, Resque and DelayedJob. PR#3636Bugfix: DelayedJob instrumentation no longer reinstalls itself on every worker under prepend mode
When DelayedJob instrumentation is installed via prepend (the default), creating more than one
Delayed::Workerin the same process caused the agent to log "Installing DelayedJob instrumentation" and reinitialize the plugin again for each additional worker. This was harmless but noisy; it's now only done once per process, matching the existing chain-instrumentation behavior. PR#3654Bugfix: Allowlisted configuration values are no longer case sensitive
Configuration options that validate against an allowlist now match values regardless of case. For example, setting
slow_sql.record_sqltoOBFUSCATEDorObFuScAtEdis now treated the same asobfuscated. Previously, a value with unexpected casing that wasn't an exact match would silently fall back to the default. PR#3645Bugfix: Puma instrumentation works when Puma is lazy-loaded
With
gem "puma", require: false, Puma was not yet loaded when the agent's dependency check ran, so Puma instrumentation would fail to install. The agent now recognizesPuma::RackHandleras evidence that Puma is present, fixing this issue. Thank you @jdelStrother for finding this issue and providing a solution! PR#3650rubocop/rubocop (rubocop)
v1.91.0Compare Source
New features
AllCops: FailLevel, the configuration equivalent of--fail-level. ([@bbatsov][])AllowedDirectivesoption toStyle/DisableCopsWithinSourceCodeDirective, exempting directive kinds such as generatedrubocop:todocomments. ([@bbatsov][])--changedto inspect only the files git says changed. ([@bbatsov][])--diffto preview autocorrection without writing files. ([@bbatsov][])Lint/MisplacedMagicCommentcop to flag magic comments in positions where Ruby ignores them. ([@bbatsov][])rubocop:enable-nextdirective to re-enable cops for the next statement only. ([@bbatsov][])rubocop:nextdirective, combiningpush-style+/-arguments withdisable-next's statement scope. ([@bbatsov][])Previewsection with the defaults it is expected to adopt in the next major release, applied underPreview. ([@bbatsov][])Bug fixes
Style/RedundantRegexpCharacterClasswith\8/\9. ([@bbatsov][])Layout/ElseAlignmentwhenelseis used withrescuein aclass,module, or singleton class body. ([@viralpraxis][])Layout/HashAlignmentwhen a hash value starts on the line below its key. ([@viralpraxis][])Layout/HashAlignmentwhen the first pair of a hash omits its value, and an incorrect autocorrection when a later pair does. ([@viralpraxis][])Layout/IndentationWidthon under-indented code with tab indentation. ([@Starlexxx][])Lint/RedundantCopDisableDirectivewhen a file contains more than onerubocop:push/rubocop:poppair. ([@koic][])Style/AccessModifierDeclarationswhen a body repeats the same access modifier. ([@viralpraxis][])Style/AccessModifierDeclarationswithEnforcedStyle: inlinewhen an access modifier is the body of anifwithout anelsebranch. ([@viralpraxis][])Style/ConstantVisibilitywhen a visibility declaration splats anything other than an array literal, e.g.private_constant(*constants(false)). ([@viralpraxis][])Style/DocumentationMethodwhen an inlinemodule_function/ruby2_keywordsdefis preceded by another argument. ([@viralpraxis][])Style/EndlessMethodwhen a method definition is nested inside another method definition. ([@viralpraxis][])Style/FloatDivisionwhen usingEnforcedStyle: fdivand one operand of a float division is itself a parenthesized float division. ([@viralpraxis][])Style/HashLookupMethodwhen the looked-up key is itself a hash lookup. ([@viralpraxis][])Style/HashSyntaxwhen hash rockets are enforced and a hash value repeats its key. ([@viralpraxis][])Lint/LiteralAsConditionwhen the other operand is a parenthesizedreturn. ([@Starlexxx][])Lint/ParenthesesAsGroupedExpressionwhen the parentheses containand,or,not, or a modifier expression. ([@Starlexxx][])Naming/BlockForwardingwithStyle/MethodDefParentheses. ([@Starlexxx][])Style/EndlessMethodwhen usingEnforcedStyle: require_alwaysand the method body has arescueorensureclause. ([@viralpraxis][])Style/FloatDivisionwhen usingEnforcedStyle: fdivand the divisor is a method call with parenthesized arguments. ([@viralpraxis][])Style/Forwhen usingEnforcedStyle: forand the block body has arescueorensureclause. ([@viralpraxis][])Style/GuardClausewithStyle/MissingElse. ([@Starlexxx][])Style/MethodCallWithArgsParentheseswhenEnforcedStyle: omit_parenthesesis used together withStyle/TrailingCommaInArguments. ([@viralpraxis][])Style/NestedModifier. ([@bbatsov][])Style/NonNilCheck. ([@bbatsov][])Style/Notwith a flip-flop or assignment. ([@bbatsov][])Style/RedundantDoubleSplatHashBraceswith a bracedmergeargument. ([@bbatsov][])Style/RedundantParenthesesaroundand/or. ([@bbatsov][])Style/RedundantRegexpConstructorwith%r{}delimiters. ([@bbatsov][])Layout/ArgumentAlignmentandLayout/HashAlignmentwith separator style. ([@Starlexxx][])Layout/CommentIndentationwhen many comment blocks with the same indentation are separated by empty lines. ([@Starlexxx][])Layout/EmptyLinesAfterModuleInclusionwhen a module inclusion is directly beforerescue. ([@Starlexxx][])Layout/ExtraSpacingwithForceEqualSignAlignmentandLayout/SpaceAroundOperators. ([@Starlexxx][])Layout/FirstArrayElementIndentationwithLayout/ArrayAlignmentwhenEnforcedStyle: with_fixed_indentationis configured. ([@RedZapdos123][])Layout/FirstParameterIndentationwithLayout/ParameterAlignmentwhenEnforcedStyle: with_fixed_indentationis configured. ([@RedZapdos123][])Layout/LineLengthwithSplitStrings: truewhen the split point lands on a trailing space. ([@Starlexxx][])Layout/SpaceAroundOperatorsandLayout/ExtraSpacingwithForceEqualSignAlignment: truefor aligned operator assignments. ([@Starlexxx][])Lint/AssignmentInConditionwhen an assignment is insidedefined?. ([@Starlexxx][])Style/EmptyMethodandStyle/SingleLineMethodswithAllowIfMethodIsEmpty: false. ([@Starlexxx][])Style/EndlessMethodwhen an indented method definition would exceedLayout/LineLengthonce made endless. ([@viralpraxis][])Style/EndlessMethodwhen a method body is a block spread over several lines. ([@viralpraxis][])Style/ParenthesesAroundConditionwithAllowSafeAssignment: falseandLint/AssignmentInCondition. ([@Starlexxx][])Layout/SpaceAroundBlockParametersandLayout/SpaceInsideParenswhen the two cops enforce conflicting styles for a lambda's parameter parentheses. ([@viralpraxis][])Style/NumericLiteralPrefixwith signed literals. ([@dylanpulver][])Lint/CopDirectiveSyntaxfalsely reporting multiple directives when valid reason text mentions another directive. ([@RedZapdos123][])Lint/DuplicateMethodsfor singleton methods in separate anonymous classes. ([@rafaelfranca][])Style/NilComparisonwith precedence-sensitive operands. ([@bbatsov][])Lint/ArgumentMismatchregistering false positives forFoo.newcalls, which are documented as out of scope but were checked against whichevernewthe project index could reach. ([@HoneyryderChuck][])Lint/ArgumentMismatchregistering false positives for calls that resolve to a private method onObject, such as a baredefwritten at the top level of a DSL file. ([@HoneyryderChuck][])rubocop:push+Coparguments enable cops that are disabled in the configuration. ([@bbatsov][])Excludewith the default configuration and with inherited files underPreview. ([@bbatsov][])RemoteConfigfailing to follow relative HTTP redirects for remote configuration files. ([@RedZapdos123][])Style/DataInheritanceto not register an offense when the class body defines constants, nested classes, or nested modules. ([@MatheusRich][])Style/StructInheritanceto not register an offense when the class body defines constants, nested classes, or nested modules. ([@MatheusRich][])Changes
Metrics/MethodLength,Metrics/AbcSize,Metrics/ClassLength,Metrics/ModuleLength,Metrics/CyclomaticComplexity,Metrics/PerceivedComplexity,Metrics/BlockLength,Metrics/ParameterListsandMetrics/BlockNestingunderPreview, ahead of them being disabled by default in RuboCop 2.0. ([@bbatsov][])Style/IfUnlessModifier,Style/GuardClause,Style/Next,Style/ClassAndModuleChildren,Style/DoubleNegation,Style/NumericPredicate,Style/SpecialGlobalVars,Style/PerlBackrefs,Style/FrozenStringLiteralComment,Style/FormatStringToken,Style/FormatString,Style/RegexpLiteral,Style/SignalException,Style/Lambda,Style/ParallelAssignment,Style/RaiseArgs,Style/ModuleFunction,Style/BlockDelimiters,Style/NumericLiterals,Style/NegatedIf,Naming/VariableNumber,Naming/HeredocDelimiterNaming,Layout/EmptyLineAfterGuardClauseandBundler/OrderedGemsunderPreview, ahead of them being disabled by default in RuboCop 2.0. ([@bbatsov][])AllCops: FailLeveltowarningunderPreview, so that style offenses are reported without failing the build, ahead of it becoming the default in RuboCop 2.0. ([@bbatsov][])EnforcedStyleofStyle/StringLiterals,Style/StringLiteralsInInterpolation,Layout/CaseIndentation,Layout/EndAlignment,Layout/MultilineMethodCallIndentation,Layout/MultilineOperationIndentation,Layout/FirstHashElementIndentation,Layout/FirstArrayElementIndentation,Layout/ParameterAlignment,Layout/ArgumentAlignment,Style/EmptyMethod,Style/Alias,Style/RescueStandardErrorandStyle/TernaryParenthesesunderPreview, ahead of them becoming the defaults in RuboCop 2.0. ([@bbatsov][])EnforcedStyleofStyle/SymbolArrayandStyle/WordArraytobracketsunderPreview, ahead of it becoming the default in RuboCop 2.0. ([@bbatsov][])Securitycops now report aswarningandMetricscops asrefactor. ([@bbatsov][])Style/DocumentationunderPreview, ahead of it being disabled by default in RuboCop 2.0. ([@bbatsov][])Lint/CopDirectiveSyntaxby default, so directives that silently disable nothing are reported. ([@bbatsov][])Style/DirectiveScopeconvert single-statement signedpush/popscopes andenable/disablepairs to thenext,enable-nextanddisable-nextforms. ([@bbatsov][])AllowedCopsandDisallowedCopsofStyle/DisableCopsWithinSourceCodeDirectivematch department names as well as cop names. ([@bbatsov][])Style/DoubleCopDisableDirective, superseded byLint/CopDirectiveSyntax, which now reports and corrects more than one directive on a line. ([@bbatsov][])warn_indentas a magic comment. This fixes a false positive forLayout/EmptyLineAfterMagicCommentand makesLint/OrderedMagicCommentsandStyle/MagicCommentFormataware of it. ([@koic][])AllowTrailingCommentoption ofStyle/DisableCopsWithinSourceCodeDirectivetoAllowWithReason. ([@bbatsov][])SeleniumHQ/selenium (selenium-webdriver)
v4.49.0=========================
simplecov-ruby/simplecov (simplecov)
v1.3.1Compare Source
==================
Bugfixes
cover_viewscompiles templates on Rails main again. Rails removedActionView::Template.registered_template_handler; the lookup readsActionView::Template::Handlers.template_handlersand still skips an extension with no handler. See #1300.require "simplecov"works again on JRuby on Windows, where 1.3.0 raisedLoadError: Could not open library '.../libprism.dll'. Prism's FFI backend cannot open its native library there, and 1.3.0 required Prism as soon as SimpleCov loaded. Prism now loads only when branch or method coverage needs the static extractor, which a line-only run never does. Where it cannot load at all, the extractor falls back to empty branch and method tables for never-loaded files, as it did before 1.3.0. See #1299.simplecov affected --runworks on JRuby on Windows, where it crashed withNoMethodErrorbecauseProcess.wait2answers no status there. On that platform the runner starts throughKernel#systeminstead.simplecov serverefuses a symlink that points outside the report on JRuby on Windows too. JRuby'sFile.realpathfollows no symlinks there, soservewould have served the file the link pointed to, andsimplecov cleanand thecoverage.jsonlookup compared paths that were never resolved. On JRuby the CLI now resolves paths through the JDK.dblock/strava-ruby-client (strava-ruby-client)
v3.1.0Compare Source
club_activities,club_members, andclub_admins, which Strava retired on September 1, 2026 - @dblock, @Copilot.danger-pr-commentreusable workflow - @dblock, @Copilot.Danger Commentworkflow failing with acontents: nonepermissions error - @dblock.revoke, deprecatingdeauthorize, per Strava's June 2026/2027 developer program changes - @dblock.total_elevation_gain,total_elevation_lossand formatted helpers toStrava::Models::Stream, computed from altitude stream data - @dblock.rake spec:integration- @dblock.explore_segmentsandstar_segmentraisingUncaughtThrowErrorinstead ofArgumentErrorfor missing required arguments - @dblock.start_date_localto always derive the timezone offset from the difference betweenstart_dateandstart_date_local, since Strava'stimezoneproperty does not account for daylight saving time - @dblock.coveralls_reborn/COVERALLS_REPO_TOKENtocoverallsapp/github-action/GITHUB_TOKEN- @dblock.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.