From 35ca382ec062b6e1c71bc29bbe121440e4202dfa Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 5 Oct 2023 08:46:37 +0000 Subject: [PATCH 01/11] Bump kt-paperclip from 7.2.0 to 7.2.1 Bumps [kt-paperclip](https://github.com/kreeti/kt-paperclip) from 7.2.0 to 7.2.1. - [Release notes](https://github.com/kreeti/kt-paperclip/releases) - [Changelog](https://github.com/kreeti/kt-paperclip/blob/master/NEWS) - [Commits](https://github.com/kreeti/kt-paperclip/compare/v7.2.0...v7.2.1) --- updated-dependencies: - dependency-name: kt-paperclip dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- Gemfile.lock | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index 342427c1f..c43a6efae 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -273,7 +273,7 @@ GEM activerecord kaminari-core (= 1.2.2) kaminari-core (1.2.2) - kt-paperclip (7.2.0) + kt-paperclip (7.2.1) activemodel (>= 4.2.0) activesupport (>= 4.2.0) marcel (~> 1.0.1) @@ -299,9 +299,9 @@ GEM memoizable (0.4.2) thread_safe (~> 0.3, >= 0.3.1) method_source (1.0.0) - mime-types (3.4.1) + mime-types (3.5.1) mime-types-data (~> 3.2015) - mime-types-data (3.2023.0218.1) + mime-types-data (3.2023.1003) mini_mime (1.1.5) mini_portile2 (2.8.4) minitest (5.20.0) From c1176e1cd49b3db112406df95999dd1fc2c3301c Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 12 Oct 2023 04:21:18 +0000 Subject: [PATCH 02/11] Bump devise from 4.9.2 to 4.9.3 Bumps [devise](https://github.com/heartcombo/devise) from 4.9.2 to 4.9.3. - [Release notes](https://github.com/heartcombo/devise/releases) - [Changelog](https://github.com/heartcombo/devise/blob/main/CHANGELOG.md) - [Commits](https://github.com/heartcombo/devise/compare/v4.9.2...v4.9.3) --- updated-dependencies: - dependency-name: devise dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- Gemfile.lock | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index eaa7982c9..8c50d046e 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -131,7 +131,7 @@ GEM aws-sigv4 (1.6.0) aws-eventstream (~> 1, >= 1.0.2) base64 (0.1.1) - bcrypt (3.1.18) + bcrypt (3.1.19) bcrypt_pbkdf (1.1.0) bootsnap (1.16.0) msgpack (~> 1.2) @@ -186,7 +186,7 @@ GEM database_cleaner-core (~> 2.0.0) database_cleaner-core (2.0.1) date (3.3.3) - devise (4.9.2) + devise (4.9.3) bcrypt (~> 3.0) orm_adapter (~> 0.1) railties (>= 4.1.0) @@ -287,7 +287,7 @@ GEM llhttp-ffi (0.4.0) ffi-compiler (~> 1.0) rake (~> 13.0) - loofah (2.21.3) + loofah (2.21.4) crass (~> 1.0.2) nokogiri (>= 1.12.0) mail (2.8.1) @@ -392,7 +392,7 @@ GEM redis (4.8.1) regexp_parser (2.8.1) require_all (3.0.0) - responders (3.1.0) + responders (3.1.1) actionpack (>= 5.2) railties (>= 5.2) rexml (3.2.6) From e4e8772f2d185f98546e2b5e82b6ad4f5bc6a971 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 18 Oct 2023 04:48:05 +0000 Subject: [PATCH 03/11] Bump capistrano from 3.17.3 to 3.18.0 Bumps [capistrano](https://github.com/capistrano/capistrano) from 3.17.3 to 3.18.0. - [Release notes](https://github.com/capistrano/capistrano/releases) - [Commits](https://github.com/capistrano/capistrano/compare/v3.17.3...v3.18.0) --- updated-dependencies: - dependency-name: capistrano dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- Gemfile.lock | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index eaa7982c9..dfc3c41b4 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -103,7 +103,7 @@ GEM activerecord (>= 4.2) addressable (2.8.5) public_suffix (>= 2.0.2, < 6.0) - airbrussh (1.4.1) + airbrussh (1.5.0) sshkit (>= 1.6.1, != 1.7.0) annotate (3.2.0) activerecord (>= 3.2, < 8.0) @@ -141,7 +141,7 @@ GEM buftok (0.3.0) builder (3.2.4) byebug (11.1.3) - capistrano (3.17.3) + capistrano (3.18.0) airbrussh (>= 1.0.0) i18n rake (>= 10.0.0) @@ -319,7 +319,7 @@ GEM net-ssh (>= 2.6.5, < 8.0.0) net-smtp (0.4.0) net-protocol - net-ssh (7.1.0) + net-ssh (7.2.0) nio4r (2.5.9) nokogiri (1.15.4) mini_portile2 (~> 2.8.2) From eeb7d2e826bd60477ddf5662f5198cdcb7881b51 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 7 Nov 2023 05:10:23 +0000 Subject: [PATCH 04/11] Bump appsignal from 3.4.13 to 3.4.14 Bumps [appsignal](https://github.com/appsignal/appsignal-ruby) from 3.4.13 to 3.4.14. - [Changelog](https://github.com/appsignal/appsignal-ruby/blob/main/CHANGELOG.md) - [Commits](https://github.com/appsignal/appsignal-ruby/compare/v3.4.13...v3.4.14) --- updated-dependencies: - dependency-name: appsignal dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- Gemfile.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Gemfile.lock b/Gemfile.lock index 0c05fea82..c42994837 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -108,7 +108,7 @@ GEM annotate (3.2.0) activerecord (>= 3.2, < 8.0) rake (>= 10.4, < 14.0) - appsignal (3.4.13) + appsignal (3.4.14) rack arbre (1.5.0) activesupport (>= 3.0.0, < 7.1) From 6700a1370c45ff94c03be8102524e4722efffac6 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 13 Nov 2023 04:58:27 +0000 Subject: [PATCH 05/11] Bump sidekiq-unique-jobs from 7.1.30 to 7.1.31 Bumps [sidekiq-unique-jobs](https://github.com/mhenrixon/sidekiq-unique-jobs) from 7.1.30 to 7.1.31. - [Release notes](https://github.com/mhenrixon/sidekiq-unique-jobs/releases) - [Changelog](https://github.com/mhenrixon/sidekiq-unique-jobs/blob/main/CHANGELOG.md) - [Commits](https://github.com/mhenrixon/sidekiq-unique-jobs/compare/v7.1.30...v7.1.31) --- updated-dependencies: - dependency-name: sidekiq-unique-jobs dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- Gemfile.lock | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index 0c05fea82..5d18490b8 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -452,7 +452,7 @@ GEM connection_pool (>= 2.2.5, < 3) rack (~> 2.0) redis (>= 4.5.0, < 5) - sidekiq-unique-jobs (7.1.30) + sidekiq-unique-jobs (7.1.31) brpoplpush-redis_script (> 0.1.1, <= 2.0.0) concurrent-ruby (~> 1.0, >= 1.0.5) redis (< 5.0) @@ -497,7 +497,7 @@ GEM rubocop-performance (~> 1.19.1) terrapin (0.6.0) climate_control (>= 0.0.3, < 1.0) - thor (1.2.2) + thor (1.3.0) thread_safe (0.3.6) tilt (2.1.0) timeout (0.4.0) From 0366ea79b8a633fd2bde9aa68d8c3c969198ba5c Mon Sep 17 00:00:00 2001 From: Agnieszka Figiel Date: Tue, 14 Nov 2023 09:02:58 +0100 Subject: [PATCH 06/11] Updated capistrano lock --- config/deploy.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/deploy.rb b/config/deploy.rb index 18c79174b..8a552088d 100644 --- a/config/deploy.rb +++ b/config/deploy.rb @@ -1,5 +1,5 @@ # config valid for current version and patch releases of Capistrano -lock '~> 3.17.0' +lock '~> 3.18.0' set :application, 'trase' set :repo_url, 'git@github.com:Vizzuality/trase.git' From da73011a6a3ef3e4241ca1c7eb80ab413cf4f023 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 14 Nov 2023 08:25:20 +0000 Subject: [PATCH 07/11] Bump bootsnap from 1.16.0 to 1.17.0 Bumps [bootsnap](https://github.com/Shopify/bootsnap) from 1.16.0 to 1.17.0. - [Changelog](https://github.com/Shopify/bootsnap/blob/main/CHANGELOG.md) - [Commits](https://github.com/Shopify/bootsnap/compare/v1.16.0...v1.17.0) --- updated-dependencies: - dependency-name: bootsnap dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- Gemfile.lock | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index e131f3e8d..a634b816a 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -133,7 +133,7 @@ GEM base64 (0.1.1) bcrypt (3.1.19) bcrypt_pbkdf (1.1.0) - bootsnap (1.16.0) + bootsnap (1.17.0) msgpack (~> 1.2) brpoplpush-redis_script (0.1.3) concurrent-ruby (~> 1.0, >= 1.0.5) @@ -305,7 +305,7 @@ GEM mini_mime (1.1.5) mini_portile2 (2.8.4) minitest (5.20.0) - msgpack (1.6.0) + msgpack (1.7.2) multipart-post (2.3.0) naught (1.1.0) net-imap (0.4.0) From 06965bb5a25701ba4e48298d305b3a8b34427d26 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 14 Nov 2023 08:27:41 +0000 Subject: [PATCH 08/11] Bump activeadmin_addons from 1.10.0 to 1.10.1 Bumps [activeadmin_addons](https://github.com/platanus/activeadmin_addons) from 1.10.0 to 1.10.1. - [Release notes](https://github.com/platanus/activeadmin_addons/releases) - [Changelog](https://github.com/platanus/activeadmin_addons/blob/master/CHANGELOG.md) - [Commits](https://github.com/platanus/activeadmin_addons/compare/v1.10.0...v1.10.1) --- updated-dependencies: - dependency-name: activeadmin_addons dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- Gemfile.lock | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index e131f3e8d..5b58f1702 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -65,7 +65,7 @@ GEM kaminari (~> 1.0, >= 1.2.1) railties (>= 6.1, < 7.1) ransack (>= 2.1.1, < 4) - activeadmin_addons (1.10.0) + activeadmin_addons (1.10.1) active_material railties redcarpet @@ -185,7 +185,7 @@ GEM activerecord (>= 5.a) database_cleaner-core (~> 2.0.0) database_cleaner-core (2.0.1) - date (3.3.3) + date (3.3.4) devise (4.9.3) bcrypt (~> 3.0) orm_adapter (~> 0.1) @@ -253,7 +253,7 @@ GEM railties (>= 5.2, < 7.1) responders (>= 2, < 4) jmespath (1.6.2) - jquery-rails (4.5.1) + jquery-rails (4.6.0) rails-dom-testing (>= 1, < 3) railties (>= 4.2.0) thor (>= 0.14, < 2.0) @@ -287,7 +287,7 @@ GEM llhttp-ffi (0.4.0) ffi-compiler (~> 1.0) rake (~> 13.0) - loofah (2.21.4) + loofah (2.22.0) crass (~> 1.0.2) nokogiri (>= 1.12.0) mail (2.8.1) @@ -303,17 +303,17 @@ GEM mime-types-data (~> 3.2015) mime-types-data (3.2023.1003) mini_mime (1.1.5) - mini_portile2 (2.8.4) + mini_portile2 (2.8.5) minitest (5.20.0) msgpack (1.6.0) multipart-post (2.3.0) naught (1.1.0) - net-imap (0.4.0) + net-imap (0.4.5) date net-protocol net-pop (0.1.2) net-protocol - net-protocol (0.2.1) + net-protocol (0.2.2) timeout net-scp (4.0.0) net-ssh (>= 2.6.5, < 8.0.0) @@ -339,7 +339,7 @@ GEM public_suffix (5.0.3) puma (6.4.0) nio4r (~> 2.0) - racc (1.7.1) + racc (1.7.3) rack (2.2.8) rack-cors (2.0.1) rack (>= 2.0.0) @@ -380,7 +380,7 @@ GEM rake (>= 12.2) thor (~> 1.0) rainbow (3.1.1) - rake (13.0.6) + rake (13.1.0) ransack (3.2.1) activerecord (>= 6.1.5) activesupport (>= 6.1.5) @@ -497,10 +497,10 @@ GEM rubocop-performance (~> 1.19.1) terrapin (0.6.0) climate_control (>= 0.0.3, < 1.0) - thor (1.2.2) + thor (1.3.0) thread_safe (0.3.6) - tilt (2.1.0) - timeout (0.4.0) + tilt (2.3.0) + timeout (0.4.1) turbolinks (5.2.1) turbolinks-source (~> 5.2) turbolinks-source (5.2.0) From 39bca8b383906b980670c48ecf5b4c8ffeb61dde Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 14 Nov 2023 08:30:17 +0000 Subject: [PATCH 09/11] Bump rubocop and standard Bumps [rubocop](https://github.com/rubocop/rubocop) and [standard](https://github.com/standardrb/standard). These dependencies needed to be updated together. Updates `rubocop` from 1.56.4 to 1.57.2 - [Release notes](https://github.com/rubocop/rubocop/releases) - [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.md) - [Commits](https://github.com/rubocop/rubocop/compare/v1.56.4...v1.57.2) Updates `standard` from 1.31.2 to 1.32.0 - [Release notes](https://github.com/standardrb/standard/releases) - [Changelog](https://github.com/standardrb/standard/blob/main/CHANGELOG.md) - [Commits](https://github.com/standardrb/standard/compare/v1.31.2...v1.32.0) --- updated-dependencies: - dependency-name: rubocop dependency-type: direct:development update-type: version-update:semver-minor - dependency-name: standard dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- Gemfile.lock | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index 3f43b6472..5827e8468 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -130,7 +130,7 @@ GEM aws-sigv4 (~> 1.6) aws-sigv4 (1.6.0) aws-eventstream (~> 1, >= 1.0.2) - base64 (0.1.1) + base64 (0.2.0) bcrypt (3.1.19) bcrypt_pbkdf (1.1.0) bootsnap (1.16.0) @@ -339,7 +339,7 @@ GEM public_suffix (5.0.3) puma (6.4.0) nio4r (~> 2.0) - racc (1.7.1) + racc (1.7.3) rack (2.2.8) rack-cors (2.0.1) rack (>= 2.0.0) @@ -415,19 +415,18 @@ GEM rspec-mocks (~> 3.12) rspec-support (~> 3.12) rspec-support (3.12.1) - rubocop (1.56.4) - base64 (~> 0.1.1) + rubocop (1.57.2) json (~> 2.3) language_server-protocol (>= 3.17.0) parallel (~> 1.10) - parser (>= 3.2.2.3) + parser (>= 3.2.2.4) rainbow (>= 2.2.2, < 4.0) regexp_parser (>= 1.8, < 3.0) rexml (>= 3.2.5, < 4.0) rubocop-ast (>= 1.28.1, < 2.0) ruby-progressbar (~> 1.7) unicode-display_width (>= 2.4.0, < 3.0) - rubocop-ast (1.29.0) + rubocop-ast (1.30.0) parser (>= 3.2.1.0) rubocop-performance (1.19.1) rubocop (>= 1.7.0, < 2.0) @@ -483,10 +482,10 @@ GEM net-scp (>= 1.1.2) net-ssh (>= 2.8.0) staccato (0.5.3) - standard (1.31.2) + standard (1.32.0) language_server-protocol (~> 3.17.0.2) lint_roller (~> 1.0) - rubocop (~> 1.56.4) + rubocop (~> 1.57.2) standard-custom (~> 1.0.0) standard-performance (~> 1.2) standard-custom (1.0.2) From b570d602d6e9da8b5456b4dcacc5ac94eb6370ac Mon Sep 17 00:00:00 2001 From: Agnieszka Figiel Date: Tue, 14 Nov 2023 09:48:45 +0100 Subject: [PATCH 10/11] Updated dependabot config to only notify of major versions --- .github/dependabot.yml | 71 ++---------------------------------------- 1 file changed, 3 insertions(+), 68 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 13daadf1b..2426a578d 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -3,75 +3,10 @@ updates: - package-ecosystem: bundler directory: "/" schedule: - interval: daily - time: "04:00" - open-pull-requests-limit: 10 + interval: weekly ignore: - - dependency-name: ckeditor - versions: - - ">= 5.a, < 6" - - dependency-name: json-schema - versions: - - "> 2.8.0, < 2.9" - - dependency-name: rack - versions: - - ">= 2.1.a, < 2.2" - - dependency-name: sprockets - versions: - - ">= 4.a, < 5" - - dependency-name: sidekiq-unique-jobs - versions: - - 7.0.4 - - 7.0.5 - - 7.0.7 - - 7.0.8 - - dependency-name: oj - versions: - - 3.11.3 - - 3.11.4 - - dependency-name: aws-sdk-s3 - versions: - - 1.88.1 - - 1.88.2 - - 1.89.0 - - 1.90.0 - - 1.91.0 - - 1.92.0 - - 1.93.0 - - 1.93.1 - - dependency-name: rubocop - versions: - - 1.12.1 - - 1.9.0 - - 1.9.1 - - dependency-name: rubocop-performance - versions: - - 1.10.2 - - dependency-name: bootsnap - versions: - - 1.7.2 - - 1.7.3 - - dependency-name: listen - versions: - - 3.4.1 - - 3.5.0 - - dependency-name: appsignal - versions: - - 2.11.9 - - 3.0.0 - - 3.0.1 - - dependency-name: webmock - versions: - - 3.11.1 - - 3.11.3 - - 3.12.0 - - 3.12.1 - - dependency-name: rails - versions: - - 5.2.4.5 - - dependency-name: puma - versions: - - 5.2.0 + - dependency-name: "*" + update-types: ["version-update:semver-patch", "version-update:semver-minor"] - package-ecosystem: github-actions directory: "/" schedule: From fac96a4eb943a0089a35a6ef7b6ec4d167b55121 Mon Sep 17 00:00:00 2001 From: Agnieszka Figiel Date: Tue, 14 Nov 2023 11:16:16 +0100 Subject: [PATCH 11/11] Revert "Bump rubocop and standard" This reverts commit 39bca8b383906b980670c48ecf5b4c8ffeb61dde. --- Gemfile.lock | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index 79e8f3f54..f1584de22 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -130,7 +130,7 @@ GEM aws-sigv4 (~> 1.6) aws-sigv4 (1.6.0) aws-eventstream (~> 1, >= 1.0.2) - base64 (0.2.0) + base64 (0.1.1) bcrypt (3.1.19) bcrypt_pbkdf (1.1.0) bootsnap (1.17.0) @@ -339,7 +339,7 @@ GEM public_suffix (5.0.3) puma (6.4.0) nio4r (~> 2.0) - racc (1.7.3) + racc (1.7.1) rack (2.2.8) rack-cors (2.0.1) rack (>= 2.0.0) @@ -415,18 +415,19 @@ GEM rspec-mocks (~> 3.12) rspec-support (~> 3.12) rspec-support (3.12.1) - rubocop (1.57.2) + rubocop (1.56.4) + base64 (~> 0.1.1) json (~> 2.3) language_server-protocol (>= 3.17.0) parallel (~> 1.10) - parser (>= 3.2.2.4) + parser (>= 3.2.2.3) rainbow (>= 2.2.2, < 4.0) regexp_parser (>= 1.8, < 3.0) rexml (>= 3.2.5, < 4.0) rubocop-ast (>= 1.28.1, < 2.0) ruby-progressbar (~> 1.7) unicode-display_width (>= 2.4.0, < 3.0) - rubocop-ast (1.30.0) + rubocop-ast (1.29.0) parser (>= 3.2.1.0) rubocop-performance (1.19.1) rubocop (>= 1.7.0, < 2.0) @@ -482,10 +483,10 @@ GEM net-scp (>= 1.1.2) net-ssh (>= 2.8.0) staccato (0.5.3) - standard (1.32.0) + standard (1.31.2) language_server-protocol (~> 3.17.0.2) lint_roller (~> 1.0) - rubocop (~> 1.57.2) + rubocop (~> 1.56.4) standard-custom (~> 1.0.0) standard-performance (~> 1.2) standard-custom (1.0.2)