Skip to content

build(deps): bump addressable from 2.8.8 to 2.9.0 in the bundler group across 1 directory#106

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/bundler-2ba255671e
Closed

build(deps): bump addressable from 2.8.8 to 2.9.0 in the bundler group across 1 directory#106
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/bundler-2ba255671e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the bundler group with 1 update in the / directory: addressable.

Updates addressable from 2.8.8 to 2.9.0

Changelog

Sourced from addressable's changelog.

Addressable 2.9.0

  • fixes ReDoS vulnerability in Addressable::Template#match (fixes incomplete remediation in 2.8.10)

Addressable 2.8.10

  • fixes ReDoS vulnerability in Addressable::Template#match

Addressable 2.8.9

  • Reduce gem size by excluding test files (#569)
  • No need for bundler as development dependency (#571, 5fc1d93)
  • idna/pure: stop building the useless COMPOSITION_TABLE (removes the Addressable::IDNA::COMPOSITION_TABLE constant) (#564)

#569: sporkmonger/addressable#569 #571: sporkmonger/addressable#571 #564: sporkmonger/addressable#564

Commits
  • 0c3e858 Revving version and changelog
  • 91915c1 Fixing additional vulnerable paths
  • a091e39 Add many more adversarial test cases to ensure we don't have any ReDoS regres...
  • 463a819 Regenerate gemspec on newer rubygems
  • 0afcb0b Improve from O(n^2) to O(n)
  • c87f768 Fix a ReDoS vulnerability in URI template matching
  • 0d7e9b2 Fix links for 2.8.9 in CHANGELOG (#573)
  • e209120 Update version, gemspec, and CHANGELOG for 2.8.9 (#572)
  • 3875874 Reduce gem size by excluding test files (#569)
  • 3e57cc6 CI: back to windows-2022 for MRI job
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Apr 8, 2026
@github-actions

github-actions Bot commented Apr 8, 2026

Copy link
Copy Markdown

Triggered from #106 by @​dependabot[bot].

Checking if we can fast forward main (08e3c7e) to dependabot/bundler/bundler-2ba255671e (113e345).

Target branch (main):

commit 08e3c7e3c4f3c915a0d1e61f9aecb4e1f820e982 (HEAD -> main, origin/main)
Author: Noah Sherwin <noahrsherwin@gmail.com>
Date:   Wed Apr 1 19:18:14 2026 -0700

    ci(build): limits perms to `content: read`

Pull request (dependabot/bundler/bundler-2ba255671e):

commit 113e3457cc3d6afcab97917193fcdba773771d0a (pull_request/dependabot/bundler/bundler-2ba255671e)
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date:   Wed Apr 8 09:13:32 2026 +0000

    build(deps): bump addressable in the bundler group across 1 directory
    
    Bumps the bundler group with 1 update in the / directory: [addressable](https://github.com/sporkmonger/addressable).
    
    
    Updates `addressable` from 2.8.8 to 2.9.0
    - [Changelog](https://github.com/sporkmonger/addressable/blob/main/CHANGELOG.md)
    - [Commits](https://github.com/sporkmonger/addressable/compare/addressable-2.8.8...addressable-2.9.0)
    
    ---
    updated-dependencies:
    - dependency-name: addressable
      dependency-version: 2.9.0
      dependency-type: indirect
      dependency-group: bundler
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>

It is possible to fast forward main (08e3c7e) to dependabot/bundler/bundler-2ba255671e (113e345). If you have write access to the target repository, you can add a comment with /fast-forward to fast forward main to dependabot/bundler/bundler-2ba255671e.

Bumps the bundler group with 1 update in the / directory: [addressable](https://github.com/sporkmonger/addressable).


Updates `addressable` from 2.8.8 to 2.9.0
- [Changelog](https://github.com/sporkmonger/addressable/blob/main/CHANGELOG.md)
- [Commits](sporkmonger/addressable@addressable-2.8.8...addressable-2.9.0)

---
updated-dependencies:
- dependency-name: addressable
  dependency-version: 2.9.0
  dependency-type: indirect
  dependency-group: bundler
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/bundler/bundler-2ba255671e branch from 113e345 to 227fa6b Compare April 17, 2026 18:51
@github-actions

Copy link
Copy Markdown

Triggered from #106 by @​dependabot[bot].

Checking if we can fast forward main (24cb1ba) to dependabot/bundler/bundler-2ba255671e (227fa6b).

Target branch (main):

commit 24cb1bac8e82ceb373fb943e32a4f5b490342b60 (HEAD -> main, origin/main)
Author: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Date:   Thu Apr 16 09:31:10 2026 +0000

    chore(deps): update dependency rake to "~> 13.4.0"

Pull request (dependabot/bundler/bundler-2ba255671e):

commit 227fa6b370d8e7a180790cb08d81bbb54af24b7f (pull_request/dependabot/bundler/bundler-2ba255671e)
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date:   Fri Apr 17 18:51:49 2026 +0000

    build(deps): bump addressable in the bundler group across 1 directory
    
    Bumps the bundler group with 1 update in the / directory: [addressable](https://github.com/sporkmonger/addressable).
    
    
    Updates `addressable` from 2.8.8 to 2.9.0
    - [Changelog](https://github.com/sporkmonger/addressable/blob/main/CHANGELOG.md)
    - [Commits](https://github.com/sporkmonger/addressable/compare/addressable-2.8.8...addressable-2.9.0)
    
    ---
    updated-dependencies:
    - dependency-name: addressable
      dependency-version: 2.9.0
      dependency-type: indirect
      dependency-group: bundler
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>

It is possible to fast forward main (24cb1ba) to dependabot/bundler/bundler-2ba255671e (227fa6b). If you have write access to the target repository, you can add a comment with /fast-forward to fast forward main to dependabot/bundler/bundler-2ba255671e.

@dependabot @github

dependabot Bot commented on behalf of github Apr 17, 2026

Copy link
Copy Markdown
Contributor Author

Looks like addressable is no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Apr 17, 2026
@dependabot dependabot Bot deleted the dependabot/bundler/bundler-2ba255671e branch April 17, 2026 19:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants