Bump sinatra, rack, sinatra-contrib, activerecord, thin and rubocop #130
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.



Bumps sinatra, rack, sinatra-contrib, activerecord, thin and rubocop. These dependencies needed to be updated together.
Updates
sinatrafrom 2.2.3 to 4.2.1Changelog
Sourced from sinatra's changelog.
... (truncated)
Commits
599a0074.2.1 release (#2125)2c7f8dbRevert "PATH_INFOcan never be empty." (#2124)f2ad45f4.2.0 release (#2122)3fe8c38Fix regex inetag_matches?to prevent ReDoS (#2121)fa99a21PATH_INFOcan never be empty. (#2114)ea0d3faSkip broken tests. (#2115)5e15985Sync changelog for v4.0.191cfb54Add :static_headers setting for custom headers in static file responses (#2089)c918134Setrubygems_mfa_requiredfor thesinatragem (#2087)ac3ff23README: Remove duplicate mention of installing puma (#2091)Updates
rackfrom 2.2.6.4 to 3.2.3Release notes
Sourced from rack's releases.
... (truncated)
Changelog
Sourced from rack's changelog.
... (truncated)
Commits
32bf888Bump patch version.e179614Unbounded read inRack::Requestform parsing can lead to memory exhaustion.57277b7Improper handling of proxy headers inRack::Sendfilemay allow proxy bypass.403b74bNormalize adivsories links.fb395bbFix handling ofErrno::EPIPEin multipart tests.bce149bBump patch version.3beacfcLimit amount of retained data when parsing multipart requests589127fFix denial of service vulnerbilties in multipart parsing14c8731Bump patch version.7ea1f40Support streaming bodies when usingRack::Events. (#2375)Updates
sinatra-contribfrom 2.2.3 to 4.2.1Changelog
Sourced from sinatra-contrib's changelog.
... (truncated)
Commits
599a0074.2.1 release (#2125)f2ad45f4.2.0 release (#2122)7b50a1b4.1.1 release (#2068)73f32914.1.0 release (#2063)ef00c6aFixSinatra::HamlHelpersdocs (#2046)973c936Fix compatibility with--enable-frozen-string-literal(#2033)5640495Fix typos in changelog, readme and code comments (#2006)b626e2d4.0.0 release (#1996)e56f657Require Ruby 2.7.8 as minimum Ruby version (#1993)8a17d4bAdd support for Rack 3, drop support for Rack 2 (#1857)Updates
activerecordfrom 6.1.7.10 to 8.0.3Release notes
Sourced from activerecord's releases.
... (truncated)
Changelog
Sourced from activerecord's changelog.
... (truncated)
Commits
529f933Preparing for 8.0.3 release0160f42Sync CHANGELOGs74038d7Merge pull request #55722 from kozy4324/fix-lease-sticky-flag-timing4fc9618Merge pull request #55703 from byroot/hly-fix-query-cache-system-tests-220c7cffMerge pull request #55699 from skipkayhil/hm-zlxzqwylrmlruzuq8408ba6Merge pull request #55698 from salzig/fix/respect_schema_format_in_db_schema_...e7f65a9Merge pull request #55691 from kohder/rl-id-value-alias-fix228fcf5Merge pull request #51359 from dfritsch/dfritsch/51280-polymorphic-name5456941Return early when column are empty in WhereClause#except_predicates87e495dMerge pull request #55675 from skipkayhil/hm-ouuplulxpznztlypUpdates
thinfrom 1.8.1 to 2.0.1Release notes
Sourced from thin's releases.
Changelog
Sourced from thin's changelog.
Commits
84a5188Bump patch version.3254c58Use bake for release management.20add8eTidy up license files.7c80818Add license files for ruby and gpl (#438)27d384bCorrection to uninitialized constant. Fixes #445 (#446)955db1aBump major version.a64256bRemove legacy Ruby 1.8 compatibility shims.745093dRakefile: rely on Rake's rakelib/ defaulte0577f9Fix "No such file or directory @ rb_io_reopen" error from test.de6b618Rack 3 no longer required environments (#437)Updates
rubocopfrom 1.50.2 to 1.81.1Release notes
Sourced from rubocop's releases.
... (truncated)
Changelog
Sourced from rubocop's changelog.
... (truncated)
Commits
db58831Cut 1.81.12797207Update Changelog6b2f047[Fix #14563] Fix an incorrect autocorrect forLint/DeprecatedOpenSSLConstant8260fc1Allow implicit block args when the block itself is on one line onlyc1400e7[Docs] Document--editor-modein a comment`d3ef76aReset the docs version386bf10Cut 1.81148250dUpdate Changelogface244Fix an error forStyle/NilComparisoncopd8c1d4cFix an error forInternalAffairsOnSendWithoutOnCSendwithalias_methodan...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.